๐ท๐ด
clauss
2026-10-08 20:50:35
(1 minute ago)
136.90.52.91 - - [08/Oct/2026:23:50:34 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Ma ...
show more
136.90.52.91 - - [08/Oct/2026:23:50:34 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
136.90.52.91 - - [08/Oct/2026:23:50:34 +0300] "GET /secrets.yml HTTP/2.0" 404 11817 "https://eusymphonyorchestra.eu/secrets.yml" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-10-08 20:46:33
(5 minutes ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/firebase-admin.j ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/firebase-admin.json via rule: /config
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 20:38:12
(13 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:38:05.223264 2026] [security2:error] [pid 7285:tid 7285] [client 136.90.52.91:35162] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||estellenussbaum.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "estellenussbaum.com"] [uri "/z9x8c7v6b5-debug-trigger-estellenussbaum.com"] [unique_id "asf_LZzTu-jp9-YwKNJ-EAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:18:03
(34 minutes ago)
(mod_security) mod_security (id:218420) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:218420) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:17:55.525004 2026] [security2:error] [pid 7582:tid 7582] [client 136.90.52.91:49234] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||equipoperu.org|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "equipoperu.org"] [uri "/index.php"] [unique_id "asf6cwUC4zQd7z3bMr-6lwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-08 20:01:07
(50 minutes ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 20:01:07
(50 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:01:02.080221 2026] [security2:error] [pid 29493:tid 29493] [client 136.90.52.91:54048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engelhardtkraatz.com"] [uri "/.htpasswd"] [unique_id "asf2fiFaa4UmhnG-Y-TQngAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-08 19:55:18
(56 minutes ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 19:34:03
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:33:59.877447 2026] [security2:error] [pid 2960:tid 2960] [client 136.90.52.91:59944] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ellestark.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ellestark.com"] [uri "/z9x8c7v6b5-debug-trigger-ellestark.com"] [unique_id "asfwJ0RoW2JO-pOBHPvYmgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 19:33:43
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-08 19:23:29
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-10-08 19:20:04
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-10-08 19:20:03
(1 hour ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:17:08
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.52.91 (91.52.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:17:04.423271 2026] [security2:error] [pid 5495:tid 5495] [client 136.90.52.91:46872] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elcalamo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elcalamo.com"] [uri "/z9x8c7v6b5-debug-trigger-elcalamo.com"] [unique_id "asfsMHybGbUDovZP-RdsSQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-08 19:15:57
(1 hour ago)
csagent: score 23.0: 404 noise floor x6, secrets grab x2, php 404 x1; 1 domain(s) in 5s
Web App Attack
๐ฌ๐ง
abivia
2026-10-08 19:05:10
(1 hour ago)
Abivia WAF trigger: Rule scriptKiddies: Probing for vulnerabilities uri: /z9x8c7v6b5-debug-trigger-a ...
show more
Abivia WAF trigger: Rule scriptKiddies: Probing for vulnerabilities uri: /z9x8c7v6b5-debug-trigger-abiviahost.ca
show less
Hacking