๐บ๐ธ
TPI-Abuse
2026-10-03 06:20:06
(17 minutes ago)
(mod_security) mod_security (id:949110) triggered by 136.70.51.242 (242.51.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 136.70.51.242 (242.51.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 02:19:57.140467 2026] [security2:error] [pid 24447:tid 24447] [client 136.70.51.242:55672] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "euro-theatre.com"] [uri "/z9x8c7v6b5-debug-trigger-euro-theatre.com"] [unique_id "asCejbs8KbdB4ZRdgqPGuwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-03 06:10:04
(27 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
jcbriar
2026-10-03 05:51:53
(46 minutes ago)
Searching for vulnerable scripts
Hacking
Web App Attack
Anonymous
2026-10-02 23:42:21
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
updown.io
2026-10-02 22:59:31
(7 hours ago)
{"level":"info","ts":1790981966.5189233,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790981966.5189233,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.70.51.242","remote_port":"58414","client_ip":"136.70.51.242","proto":"HTTP/2.0","method":"GET","host":"status.dtesvancouver.com","uri":"/8cu4p1jywvpb29qef5m7","headers":{"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"],"Accept-Encoding":["gzip"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.dtesvancouver.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000095482,"size":0,"status":429,"resp_headers":{"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"],"Server":["Caddy"]}}
{"level":"info","ts":1790981966.853915,"logger":"http.log.access.log1","msg
...
show less
DDoS Attack
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-02 17:59:01
(12 hours ago)
csagent: score 24.4: 404 noise floor x18, spoofed crawler UA x1, secrets grab x1; 1 domain(s) in 2s
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 17:52:47
(12 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
mnsf
2026-10-02 17:05:17
(13 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-02 16:54:13
(13 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:48:48
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.51.242 (242.51.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.51.242 (242.51.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:48:45.179403 2026] [security2:error] [pid 390:tid 390] [client 136.70.51.242:43832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||forwardti.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "forwardti.com"] [uri "/z9x8c7v6b5-debug-trigger-forwardti.com"] [unique_id "ar_ETYO9hAn9UvjlecpY1gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:35:59
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.51.242 (242.51.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.51.242 (242.51.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:35:56.236152 2026] [security2:error] [pid 19284:tid 19284] [client 136.70.51.242:38036] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jangambleandco.com|F|2"] [data ".jangambleandco.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jangambleandco.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jangambleandco.com"] [unique_id "ar-zPIQVOGoQBnTDotY8HgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 12:37:59
(17 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 12:18:39
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.51.242 (242.51.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.51.242 (242.51.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:18:34.579159 2026] [security2:error] [pid 8986:tid 8986] [client 136.70.51.242:51698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kiddocommunication.com"] [uri "/.//.env"] [unique_id "ar-hGpp-GVMZoY5HKnIVbwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:49:46
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.51.242 (242.51.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.51.242 (242.51.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:49:41.089337 2026] [security2:error] [pid 5206:tid 5266] [client 136.70.51.242:33350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fernfieldbrooks.com"] [uri "/.env.js"] [unique_id "ar-aVSZl1z5U4v4mD3zExgAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:08:31
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.51.242 (242.51.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.51.242 (242.51.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:08:26.191351 2026] [security2:error] [pid 26468:tid 26468] [client 136.70.51.242:34402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jackieherbach.com|F|2"] [data ".jackieherbach.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jackieherbach.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jackieherbach.com"] [unique_id "ar-Qqn67gQCDAVy67-bZFQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack