Anonymous
2026-10-09 20:49:00
(7 minutes ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:35:35
(20 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:35:30.486262 2026] [security2:error] [pid 19378:tid 19378] [client 136.90.9.187:50846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "communityofthecosmos.org"] [uri "/.htpasswd"] [unique_id "aslQEmWuc3Rz0LqBhGbxlQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 20:05:52
(50 minutes ago)
136.90.9.187 - - [09/Oct/2026:22:05:48 +0200] "GET /asset-manifest.json HTTP/1.1" 404 24649
136.90.9 ...
show more
136.90.9.187 - - [09/Oct/2026:22:05:48 +0200] "GET /asset-manifest.json HTTP/1.1" 404 24649
136.90.9.187 - - [09/Oct/2026:22:05:48 +0200] "GET /static/manifest.json HTTP/1.1" 404 29760
136.90.9.187 - - [09/Oct/2026:22:05:48 +0200] "GET /dist/manifest.json HTTP/1.1" 404 29760
136.90.9.187 - - [09/Oct/2026:22:05:48 +0200] "GET /oy1l0gkzvo6cqhuf25fs HTTP/1.1" 404 29760
136.90.9.187 - - [09/Oct/2026:22:05:48 +0200] "GET /webpack-stats.json HTTP/1.1" 404 29760
136.90.9.187 - - [09/Oct/2026:22:05:48 +0200] "GET /assets/manifest.json HTTP/1.1" 404 29760
136.90.9.187 - - [09/Oct/2026:22:05:49 +0200] "GET /manifest.json HTTP/1.1" 404 29760
136.90.9.187 - - [09/Oct/2026:22:05:49 +0200] "GET /graphql HTTP/1.1" 404 24649
136.90.9.187 - - [09/Oct/2026:22:05:49 +0200] "GET /signin HTTP/1.1" 404 24649
136.90.9.187 - - [09/Oct/2026:22:05:49 +0200] "GET /sign-in HTTP/1.1" 404 24649
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:53:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:53:25.062542 2026] [security2:error] [pid 9667:tid 9667] [client 136.90.9.187:34830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circleinthesquare.org"] [uri "/.htpasswd"] [unique_id "aslGNVRuP_d5EwqnLVwf9gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-10-09 19:50:15
(1 hour ago)
Attack against Apache (too many 404s)
Web App Attack
Anonymous
2026-10-09 19:30:45
(1 hour ago)
Fail2Ban apache-noscript
Bad Web Bot
๐ฉ๐ช
findlab
2026-10-09 19:25:01
(1 hour ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:16:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:16:49.943417 2026] [security2:error] [pid 24868:tid 24868] [client 136.90.9.187:42938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centralbaptistalcoa.org"] [uri "/.htpasswd"] [unique_id "ask9oWOKS9CFG7NCc_3FrQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:35:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:35:54.663085 2026] [security2:error] [pid 30041:tid 30041] [client 136.90.9.187:53734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canadianprimarysources.org"] [uri "/.htpasswd"] [unique_id "ask0Cg3DBrsGKplnu-3tKwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-09 18:33:08
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
cmbplf
2026-10-09 18:28:35
(2 hours ago)
2.435 requests with url.path *.env
1.454 requests with url.path */@fs/*
374 requests with url.pat ...
show more
2.435 requests with url.path *.env
1.454 requests with url.path */@fs/*
374 requests with url.path */proc/*
279 requests with url.path *.aws/*
243 requests with url.path *config.json
218 requests with url.path *credentials.json
209 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 18:14:35
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:14:27.811258 2026] [security2:error] [pid 5177:tid 5177] [client 136.90.9.187:48546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "burke698.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "askvA8Y3qtW4kkDPDQXY6AAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-10-09 18:03:59
(2 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /.ssh/id_rsa (HTTP/2.0 port 443, use ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.ssh/id_rsa (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)")
show less
Web App Attack
๐บ๐ธ
brightenfield
2026-10-09 17:59:56
(2 hours ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:57:31
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.9.187 (187.9.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:57:27.374125 2026] [security2:error] [pid 3620:tid 3620] [client 136.90.9.187:57876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brevardzen.org"] [uri "/.htpasswd"] [unique_id "askrB4TzyfwxEbJg-_yqmAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack