🇺🇸
chrisj
2026-09-14 07:50:26
(54 minutes ago)
[Mon Sep 14 07:50:25.137637 2026] [proxy_fcgi:error] [pid 1862933:tid 1862951] [remote 136.107.193.2 ...
show more
[Mon Sep 14 07:50:25.137637 2026] [proxy_fcgi:error] [pid 1862933:tid 1862951] [remote 136.107.193.255:57192] AH01071: Got error 'Primary script unknown'
[Mon Sep 14 07:50:25.141773 2026] [proxy_fcgi:error] [pid 1862933:tid 1862953] [remote 136.107.193.255:57192] AH01071: Got error 'Primary script unknown'
[Mon Sep 14 07:50:25.157246 2026] [proxy_fcgi:error] [pid 1862933:tid 1862976] [remote 136.107.193.255:57192] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-14 07:29:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.107.193.255 (255.193.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.193.255 (255.193.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 03:28:55.548766 2026] [security2:error] [pid 19862:tid 19862] [client 136.107.193.255:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wiszen.org"] [uri "/admin/.env"] [unique_id "aqeiNwA8dHyEj_2POyJVOAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 07:06:29
(1 hour ago)
(mod_security) mod_security (id:210580) triggered by 136.107.193.255 (255.193.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210580) triggered by 136.107.193.255 (255.193.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 03:06:22.335667 2026] [security2:error] [pid 24841:tid 24841] [client 136.107.193.255:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||autodiscover.redish.org|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "autodiscover.redish.org"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqec7gWDYHMh2ukvGcR8WAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 06:33:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.193.255 (255.193.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.193.255 (255.193.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:33:35.189806 2026] [security2:error] [pid 28718:tid 28718] [client 136.107.193.255:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.helpsavepets.org"] [uri "/.git/config"] [unique_id "aqeVP-7nfN2bfNjHPnoquwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
bigscoots.com
2026-09-14 06:25:15
(2 hours ago)
(PERMBLOCK) 136.107.193.255 (US/United States/255.193.107.136.bc.googleusercontent.com) has had more ...
show more
(PERMBLOCK) 136.107.193.255 (US/United States/255.193.107.136.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: 1; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Brute-Force
SSH
🇿🇦
conure.sh
2026-09-14 06:20:06
(2 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇩🇪
macrob
2026-09-14 04:40:19
(4 hours ago)
2026/09/14 04:40:18 [error] 1666065#1666065: *9817179 access forbidden by rule, client: 136.107.193. ...
show more
2026/09/14 04:40:18 [error] 1666065#1666065: *9817179 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "auth0.wellbin.org"
2026/09/14 04:40:18 [error] 1666068#1666068: *9817195 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "auth0.wellbin.org"
2026/09/14 04:40:18 [error] 1666068#1666068: *9817201 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /.env.js HTTP/2.0", host: "auth0.wellbin.org"
...
show less
Web App Attack
🇩🇪
macrob
2026-09-14 01:53:14
(6 hours ago)
2026/09/14 01:53:12 [error] 1442487#1442487: *9414235 access forbidden by rule, client: 136.107.193. ...
show more
2026/09/14 01:53:12 [error] 1442487#1442487: *9414235 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "alipay.wellbin.org"
2026/09/14 01:53:12 [error] 1442489#1442489: *9414243 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /.env.js HTTP/2.0", host: "alipay.wellbin.org"
2026/09/14 01:53:12 [error] 1442489#1442489: *9414245 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "alipay.wellbin.org"
...
show less
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-13 22:15:08
(10 hours ago)
Brute-Force
Web App Attack
🇩🇪
macrob
2026-09-13 20:39:53
(12 hours ago)
2026/09/13 20:39:51 [error] 1442486#1442486: *8778543 access forbidden by rule, client: 136.107.193. ...
show more
2026/09/13 20:39:51 [error] 1442486#1442486: *8778543 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "aad.wellbin.org"
2026/09/13 20:39:51 [error] 1442489#1442489: *8778549 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "aad.wellbin.org"
2026/09/13 20:39:52 [error] 1442485#1442485: *8778566 access forbidden by rule, client: 136.107.193.255, server: fn.binixo.es, request: "GET /admin/login HTTP/2.0", host: "aad.wellbin.org"
...
show less
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-13 17:55:27
(14 hours ago)
2026/09/13 18:55:25 [error] 1459171#1459171: *654661 access forbidden by rule, client: 136.107.193.2 ...
show more
2026/09/13 18:55:25 [error] 1459171#1459171: *654661 access forbidden by rule, client: 136.107.193.255, server: simetria.org, request: "GET /.env HTTP/2.0", host: "simetria.org"
136.107.193.255 - - [13/Sep/2026:18:55:25 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
2026/09/13 18:55:26 [error] 1459171#1459171: *654674 access forbidden by rule, client: 136.107.193.255, server: simetria.org, request: "GET /admin/.env HTTP/2.0", host: "simetria.org"
show less
Brute-Force
Web App Attack
🇺🇸
factor1
2026-09-13 17:53:35
(14 hours ago)
CrowdSec at saturn Reports Abuse
Web App Attack
Anonymous
2026-09-13 17:44:42
(15 hours ago)
136.107.193.255 - - [13/Sep/2026:12:44:40 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
136.107.193.255 - - [13/Sep/2026:12:44:40 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 136.107.193.255
136.107.193.255 - - [13/Sep/2026:12:44:40 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 136.107.193.255
136.107.193.255 - - [13/Sep/2026:12:44:40 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 136.107.193.255
136.107.193.255 - - [13/Sep/2026:12:44:40 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 136.107.193.255
136.107.193.255 - - [13/Sep/2026:12:44:40 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 136.107.193.255
136.107.193.255
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 17:31:34
(15 hours ago)
Logfile match
Web App Attack
🇪🇸
elcruzado.es
2026-09-13 16:25:28
(16 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.107.193.255 (US/United States/255.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.107.193.255 (US/United States/255.193.107.136.bc.googleusercontent.com)
show less
SQL Injection