๐บ๐ธ
TPI-Abuse
2026-08-07 22:34:39
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.85.67.167 (167.67.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.67.167 (167.67.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 18:34:31.478044 2026] [security2:error] [pid 535938:tid 535938] [client 136.85.67.167:35940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.infodevman.net"] [uri "/.git/config"] [unique_id "anZddwMtLfVicS57D9sh-AAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 21:45:40
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.85.67.167 (167.67.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.67.167 (167.67.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 17:45:37.166204 2026] [security2:error] [pid 2427312:tid 2427394] [client 136.85.67.167:43952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gotlib.net"] [uri "/.git/HEAD"] [unique_id "anZSAexxos_6iW-c4xtItAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-07 21:31:39
(3 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 21:25:37
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 136.85.67.167 (167.67.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.67.167 (167.67.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 17:25:33.452265 2026] [security2:error] [pid 2562133:tid 2562157] [client 136.85.67.167:59170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.appraisalteam.net"] [uri "/.hermes/.env"] [unique_id "anZNTRsxZ-sU5b0jiGWHhwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dave
2026-08-07 21:18:13
(3 weeks ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config observed_by=1_hosts hit_count=16 first_seen=2026-08-07T21:18:07Z last_seen=2026-08-07T21:18:13Z
show less
Web App Attack
๐ง๐ช
cmbplf
2026-08-07 21:14:09
(3 weeks ago)
4.706 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
๐บ๐ธ
MatCat
2026-08-07 21:05:04
(3 weeks ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
Anonymous
2026-08-07 21:02:01
(3 weeks ago)
Bot / scanning and/or hacking attempts: GET /elmah.axd HTTP/2.0, GET /server-status HTTP/2.0, GET /_ ...
show more
Bot / scanning and/or hacking attempts: GET /elmah.axd HTTP/2.0, GET /server-status HTTP/2.0, GET /__debug__/ HTTP/2.0, GET /_profiler/latest HTTP/2.0, GET /server-info HTTP/2.0, GET /_debugbar/open HTTP/2.0
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-07 20:30:47
(3 weeks ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 20:28:43
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 136.85.67.167 (167.67.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.67.167 (167.67.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 16:28:36.339364 2026] [security2:error] [pid 2968167:tid 2968167] [client 136.85.67.167:57758] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rustyog.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rustyog.net"] [uri "/rclone.conf"] [unique_id "anY_9ILh7AcAbO1cn0xhAwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-07 20:28:12
(3 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ต๐ฑ
Woytass
2026-08-07 20:13:34
(3 weeks ago)
CSF/lfd permanent block on srv1.woytas.ovh. Trigger=LF_MODSEC; ports=*; (mod_security) mod_security ...
show more
CSF/lfd permanent block on srv1.woytas.ovh. Trigger=LF_MODSEC; ports=*; (mod_security) mod_security (id:949110) triggered by 136.85.67.167 (SG/Singapore/167.67.85.136.bc.googleusercontent.com): 5 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 19:43:40
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 136.85.67.167 (167.67.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.67.167 (167.67.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 15:43:35.976248 2026] [security2:error] [pid 3103274:tid 3103274] [client 136.85.67.167:33654] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intersession.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intersession.net"] [uri "/rclone.conf"] [unique_id "anY1ZwvdvMHURlbBm6rDMAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-07 19:43:28
(3 weeks ago)
ITDATINE WEBEXPLOIT 136.85.67.167 (167.67.85.136.bc.googleusercontent.com)
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-07 19:41:00
(3 weeks ago)
Banned by Fail2Ban
Web App Attack