๐ฉ๐ช
Philister11
2026-10-11 01:16:41
(1 hour ago)
CrowdSec: crowdsecurity/http-crawl-non_statics (US/AS396982)
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-10-11 01:01:30
(2 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
Philister11
2026-10-11 00:14:32
(2 hours ago)
CrowdSec: crowdsecurity/grafana-cve-2021-43798 (US/AS396982)
Web App Attack
Hacking
๐ซ๐ท
SpaceHost-Server
2026-10-10 22:15:08
(4 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-10 20:13:34
(6 hours ago)
2026/10/10 21:13:32 [error] 4060693#4060693: *1917690 access forbidden by rule, client: 136.107.236. ...
show more
2026/10/10 21:13:32 [error] 4060693#4060693: *1917690 access forbidden by rule, client: 136.107.236.150, server: api.betatechnologies.info, request: "GET /.env HTTP/2.0", host: "api.betatechnologies.info"
136.107.236.150 - - [10/Oct/2026:21:13:32 +0100] "GET /.env HTTP/2.0" 403 95 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
2026/10/10 21:13:32 [error] 4060693#4060693: *1917690 access forbidden by rule, client: 136.107.236.150, server: api.betatechnologies.info, request: "GET /config/.env HTTP/2.0", host: "api.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
gurnip
2026-10-10 19:31:06
(7 hours ago)
Vulnerability probe of page /console, not found on the server.
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-10 19:28:58
(7 hours ago)
136.107.236.150 - - [10/Oct/2026:21:28:54 +0200] "GET /%2Fsettings HTTP/2.0" 404 293 "-" "Mozilla/5. ...
show more
136.107.236.150 - - [10/Oct/2026:21:28:54 +0200] "GET /%2Fsettings HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
136.107.236.150 - - [10/Oct/2026:21:28:54 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/2.0" 400 323 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.107.236.150 - - [10/Oct/2026:21:28:54 +0200] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/2.0" 400 323 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
136.107.236.150 - - [10/Oct/2026:21:28:54 +0200] "GET /apps/.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
136.107.236.150 - - [10/Oct/2026:21:28:54 +0200] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/2.0" 400 323 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email])"
136
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-10 19:27:17
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.236.150 (150.236.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.236.150 (150.236.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:27:13.598409 2026] [security2:error] [pid 11486:tid 11486] [client 136.107.236.150:42950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smartradios.info"] [uri "/config/.env"] [unique_id "asqRkWYxshTcDeOlMzAajAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
security.rdmc.fr
2026-10-10 19:10:50
(7 hours ago)
Web scan: multiple 4xx responses
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 19:06:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.236.150 (150.236.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.236.150 (150.236.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:06:12.080243 2026] [security2:error] [pid 8574:tid 8574] [client 136.107.236.150:54106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "russiacoin.info"] [uri "/src/.env"] [unique_id "asqMpCaFdjEbnUtdv6IClgAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-10-10 18:55:42
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.107.236.150 (US/United States/150.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.107.236.150 (US/United States/150.236.107.136.bc.googleusercontent.com)
show less
SQL Injection
๐ช๐ธ
scaballe
2026-10-10 18:48:36
(8 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 18:27:09
(8 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.107.236.150 (150.236.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210580) triggered by 136.107.236.150 (150.236.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 14:27:06.383692 2026] [security2:error] [pid 7056:tid 7056] [client 136.107.236.150:40620] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:file. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||philam.info|F|2"] [data "Matched Data: proc/self/environ found within ARGS:file: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "philam.info"] [uri "/api/system/fileView"] [unique_id "asqDegQ3Pg289Monkk1wHwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-10 18:17:08
(8 hours ago)
[Sun Oct 11 05:17:07.761931 2026] [security2:error] [pid 819997] [client 136.107.236.150:60992] [cli ...
show more
[Sun Oct 11 05:17:07.761931 2026] [security2:error] [pid 819997] [client 136.107.236.150:60992] [client 136.107.236.150] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/static/.env"] [unique_id "asqBIz8OWZ009LgtSK83wAAAAAk"]
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-10-10 18:16:19
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack