🇩🇪
Marc
2026-09-11 18:41:22
(9 hours ago)
136.107.60.52 - - [11/Sep/2026:20:41:22 +0200] "GET /dashboard HTTP/2.0" 404 291 "-" "Mozilla/5.0 (L ...
show more
136.107.60.52 - - [11/Sep/2026:20:41:22 +0200] "GET /dashboard HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36" 136.107.60.52 - - [11/Sep/2026:20:41:22 +0200] "GET /app HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36" 136.107.60.52 - - [11/Sep/2026:20:41:22 +0200] "GET /panel HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
show less
Brute-Force
🇬🇧
Aetherweb Ark
2026-09-11 18:35:09
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.107.60.52 (US/United States/52.60.107.136.b ...
show more
(mod_security) mod_security (id:949110) triggered by 136.107.60.52 (US/United States/52.60.107.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
IndigoRidge
2026-09-11 18:33:30
(9 hours ago)
136.107.60.52 - - [11/Sep/2026:14:33:29 -0400] "GET /.git/config HTTP/1.1" 404 6284 "-" "DuckAssistB ...
show more
136.107.60.52 - - [11/Sep/2026:14:33:29 -0400] "GET /.git/config HTTP/1.1" 404 6284 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
136.107.60.52 - - [11/Sep/2026:14:33:29 -0400] "GET /.aws/credentials HTTP/1.1" 404 6284 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
136.107.60.52 - - [11/Sep/2026:14:33:29 -0400] "GET /.env HTTP/1.1" 404 6284 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:32:00
(9 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.107.60.52 (52.60.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 136.107.60.52 (52.60.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:31:56.023191 2026] [security2:error] [pid 6174:tid 6174] [client 136.107.60.52:38234] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||whaleyhouse.net|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "whaleyhouse.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqRJHLSNRDw6S2Hj_IkAxAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇯🇵
weils.net
2026-09-11 18:22:27
(10 hours ago)
2026-09-12 02:22:26(GMT+8) - /wp-config.php.bak
Bad Web Bot
🇫🇮
pixiekat
2026-09-11 18:17:04
(10 hours ago)
[Fri Sep 11 19:17:04.116120 2026] [security2:error] [pid 3689055:tid 3689081] [remote 136.107.60.52: ...
show more
[Fri Sep 11 19:17:04.116120 2026] [security2:error] [pid 3689055:tid 3689081] [remote 136.107.60.52:42500] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "webkitten.net"] [uri "/"] [unique_id "aqRFoIP_4tJiCZiN3jEoRwAAFAc"]
[Fri Sep 11 19:17:04.254338 2026] [security2:error] [pid 3689055:tid 3689093] [remote 136.107.60.52:42500] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/modsecurity-crs/coreruleset/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OW
...
show less
Web App Attack
🇩🇪
LRob
2026-09-11 18:14:32
(10 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-11 18:14 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 18:08:01
(10 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.107.60.52 (52.60.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 136.107.60.52 (52.60.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:07:55.533512 2026] [security2:error] [pid 13464:tid 13464] [client 136.107.60.52:43192] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||waterspell.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "waterspell.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqRDew6lTp8v-Q2R2p6HmQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:50:45
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.107.60.52 (52.60.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.107.60.52 (52.60.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:50:38.191696 2026] [security2:error] [pid 28182:tid 28182] [client 136.107.60.52:36142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vrevgaming.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vrevgaming.net"] [uri "/rclone.conf"] [unique_id "aqQ_br8gtLyOtdXT1rQblAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 17:46:57
(10 hours ago)
Restricted File Access Attempt. Matched phrase "/proc/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇩🇪
33three
2026-09-11 17:44:43
(10 hours ago)
Fail2Ban jail WebAttack triggered
Brute-Force
🇬🇧
consul.to
2026-09-11 17:40:22
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
HamSammich
2026-09-11 17:37:55
(10 hours ago)
Automated sensor: 9 HTTPS connection/probe attempts over the last 24h (latest 2026-09-11T17:37Z).
Brute-Force
Web App Attack
Anonymous
2026-09-11 17:35:21
(10 hours ago)
136.107.60.52 detected on srv01
Brute-Force
🇮🇹
VHosting
2026-09-11 17:30:04
(10 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack