Anonymous
2026-09-29 19:30:02
(8 minutes ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:25:46
(12 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:25:43.739513 2026] [security2:error] [pid 27548:tid 27557] [client 136.90.72.86:55116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||apada.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "apada.com"] [uri "/z9x8c7v6b5-debug-trigger-apada.com"] [unique_id "arwQt1SV7nSbFARv9_VaDQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Nicos
2026-09-29 19:15:53
(22 minutes ago)
2026-09-29T21:15:52.467425+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "d ...
show more
2026-09-29T21:15:52.467425+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "domain_url": "Redacted", "event": "/0zqg5zsf69vkv3vgon2j", "host": "Redacted", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 850770, "remote": "136.90.72.86", "request_id": "da60726036f7441f95e624751e95dd3a", "runtime": 50, "schema_name": "public", "scheme": "https", "status": 404, "timestamp": "2026-09-29T19:15:52.467207", "user": "", "user_agent": "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"}
2026-09-29T21:15:52.476587+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "domain_url": "Redacted", "event": "/.vite/manifest.json", "host": "Redacted", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 850770, "remote": "136.90.72.86", "request_id": "d485945599434155bde1a464034a99ba", "runtime": 43, "schema_name": "public", "scheme": "https", "status": 404, "timestamp": "2026-09-29T19:15:52.
...
show less
Hacking
Brute-Force
Anonymous
2026-09-29 19:13:03
(25 minutes ago)
Bot / scanning and/or hacking attempts: GET /server-info HTTP/2.0, GET /server-status HTTP/2.0, GET ...
show more
Bot / scanning and/or hacking attempts: GET /server-info HTTP/2.0, GET /server-status HTTP/2.0, GET /app_dev.php HTTP/2.0, GET /api/graphql HTTP/2.0, POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, GET /i.php HTTP/2.0, GET /graphql/console HTTP/2.0, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, GET /_ignition/health-check HTTP/2.0, GET /_profiler/latest HTTP/2.0, POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil
show less
Hacking
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-29 19:00:07
(38 minutes ago)
2026/09/29 20:00:02 [error] 3532286#3532286: *1108431 access forbidden by rule, client: 136.90.72.86 ...
show more
2026/09/29 20:00:02 [error] 3532286#3532286: *1108431 access forbidden by rule, client: 136.90.72.86, server: alzulej.pt, request: "GET /autodiscover.xml/.env HTTP/2.0", host: "alzulej.pt", referrer: "https://autoconfig.alzulej.pt/.env"
2026/09/29 20:00:05 [error] 3532286#3532286: *1108431 access forbidden by rule, client: 136.90.72.86, server: alzulej.pt, request: "GET /autodiscover.xml/.env HTTP/2.0", host: "alzulej.pt", referrer: "https://autoconfig.alzulej.pt/_nuxt/../.env"
2026/09/29 20:00:05 [error] 3532288#3532288: *1108462 access forbidden by rule, client: 136.90.72.86, server: alzulej.pt, request: "GET /autodiscover.xml/laravel/.env HTTP/2.0", host: "alzulej.pt", referrer: "https://autoconfig.alzulej.pt/laravel/.env"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 18:55:41
(42 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:55:37.064849 2026] [security2:error] [pid 24379:tid 24379] [client 136.90.72.86:54732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||buffaloweddingreception.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "buffaloweddingreception.com"] [uri "/z9x8c7v6b5-debug-trigger-buffaloweddingreception.com"] [unique_id "arwJqQos5hFyUjd24EdmRAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 18:39:10
(58 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:39:04.333461 2026] [security2:error] [pid 5473:tid 5473] [client 136.90.72.86:36102] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.caravaningfigaro.com|F|2"] [data ".caravaningfigaro.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.caravaningfigaro.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.caravaningfigaro.com"] [unique_id "arwFyE34oLxZgoKV063eIwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-29 18:23:15
(1 hour ago)
Malicious activity from IP detected: crowdsecurity/http-probing.
Web App Attack
Hacking
๐ซ๐ท
Little Iguana
2026-09-29 17:38:50
(1 hour ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
Anonymous
2026-09-29 17:35:48
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-09-29 17:30:23
(2 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-29 17:24:43
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:24:37.021004 2026] [security2:error] [pid 3807:tid 3807] [client 136.90.72.86:42440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||4photogifts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "4photogifts.com"] [uri "/z9x8c7v6b5-debug-trigger-4photogifts.com"] [unique_id "arv0VZVpnQk86urWg8P2bgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-29 17:23:50
(2 hours ago)
Aggressive web search of vulnerable pages: /userfiles?path=../../../../.env /userfiles/x?path=../../ ...
show more
Aggressive web search of vulnerable pages: /userfiles?path=../../../../.env /userfiles/x?path=../../.env /docker-compose.yml /api/openapi.json ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 17:03:54
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.72.86 (86.72.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:03:48.942248 2026] [security2:error] [pid 26601:tid 26601] [client 136.90.72.86:60410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.cabanaconstructionandpaving.com|F|2"] [data ".cabanaconstructionandpaving.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.cabanaconstructionandpaving.com"] [uri "/z9x8c7v6b5-debug-trigger-autodiscover.cabanaconstructionandpaving.com"] [unique_id "arvvdDdAMCLAefXYyTj5TAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 16:44:30
(2 hours ago)
Aggressive web scan
Web App Attack