Anonymous
2026-09-23 21:23:42
(37 minutes ago)
Malicious Probing/Bad Request
Bad Web Bot
๐ฉ๐ช
palzer.IT
2026-09-23 20:18:58
(1 hour ago)
Fail2ban automatic report for plesk-apache-badbot: 136.107.71.124 - - [23/Sep/2026:22:18:35 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 136.107.71.124 - - [23/Sep/2026:22:18:35 +0200] GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? [DOMAIN_REMOVED] 403 6284 - Mozilla/5.0 (compatible; Bytespider; spider-feedback@[DOMAIN_REMOVED]) AppleWebKit/537.36
show less
Bad Web Bot
๐ซ๐ท
aki
2026-09-23 19:40:58
(2 hours ago)
Web attack blocked
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:35:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:35:16.557417 2026] [security2:error] [pid 13299:tid 13299] [client 136.107.71.124:48364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.endriss.info"] [uri "/@fs/var/task/.env"] [unique_id "arQp9HRxgkWbVXK02tKVKAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2026-09-23 19:16:21
(2 hours ago)
82 attack(s) detected, such as these: {"event":"web_block","ip":"136.107.71.124","host":"adalta.info ...
show more
82 attack(s) detected, such as these: {"event":"web_block","ip":"136.107.71.124","host":"adalta.info","request":"GET /_next/static/buildManifest.js HTTP/2.0","user_agent":"","reason":"Status-404","timestamp":"2026-09-23T19:16:21 00:00","logentry":"adalta.info 136.107.71.124 - - [23/Sep/2026:19:16:21 0000] \"GET /_next/static/buildManifest.js HTTP/2.0\" 404 3652 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36\" \"172.25.79.35:3000\""} * Report Details *: https://p4u.xyz/LQ7JWPHTQEN/1* IP Details *: https://p4u.xyz/LQ7JWPHTQEN/2
show less
Web Spam
Hacking
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-23 19:06:15
(2 hours ago)
2026/09/23 20:06:10 [error] 325888#325888: *1653850 access forbidden by rule, client: 136.107.71.124 ...
show more
2026/09/23 20:06:10 [error] 325888#325888: *1653850 access forbidden by rule, client: 136.107.71.124, server: betatechnologies.info, request: "GET /api/.env HTTP/2.0", host: "betatechnologies.info"
2026/09/23 20:06:13 [error] 325888#325888: *1653850 access forbidden by rule, client: 136.107.71.124, server: betatechnologies.info, request: "GET /admin/.env HTTP/2.0", host: "betatechnologies.info"
2026/09/23 20:06:14 [error] 325888#325888: *1653850 access forbidden by rule, client: 136.107.71.124, server: betatechnologies.info, request: "GET /src/.env HTTP/2.0", host: "betatechnologies.info"
show less
Brute-Force
Web App Attack
๐น๐ผ
tyebstx
2026-09-23 19:04:58
(2 hours ago)
Wazuh Alert Evidence: 136.107.71.124 - - [23/Sep/2026:19:04:55 +0000] "GET / HTTP/2.0" 444 0 "-" "Mo ...
show more
Wazuh Alert Evidence: 136.107.71.124 - - [23/Sep/2026:19:04:55 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-"
show less
Web App Attack
๐จ๐ญ
zynex
2026-09-23 19:04:37
(2 hours ago)
URL Probing: /src/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:57:54
(3 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:57:48.868654 2026] [security2:error] [pid 3112:tid 3112] [client 136.107.71.124:53404] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:href. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||ciid.info|F|2"] [data "Matched Data: proc/self/environ found within ARGS:href: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "ciid.info"] [uri "/_image"] [unique_id "arQhLLX2iTAbKET8CQv_XAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-09-23 18:48:23
(3 hours ago)
23/Sep/2026:20:48:22.608051 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
23/Sep/2026:20:48:22.608051 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.107.71.124] ModSecurity: Warning. Matched phrase "proc/self/environ" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "98"] [id "930120"] [msg "OS File Access Attempt"] [data "Matched Data: proc/self/environ found within ARGS:0: {\\\\x22then\\\\x22:\\\\x22$1:__proto__:then\\\\x22,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22,\\\\x22reason\\\\x22:-1,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22$b1337/\\\\x22}\\\\x22,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require('child_process').execsync('env 2>/dev/null || cat /proc/self/environ 2>/dev/null');\\\\x22,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22$1:constructor:constructor\\\\x22}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:42:51
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:42:46.199044 2026] [security2:error] [pid 10255:tid 10255] [client 136.107.71.124:55836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "freerein.info"] [uri "/@fs/src/.env"] [unique_id "arQdpqgzLiOCK9gKNyKciQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 18:37:55
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 18:11:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.71.124 (124.71.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:11:46.582737 2026] [security2:error] [pid 6831:tid 6831] [client 136.107.71.124:60110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marat.info"] [uri "/static../.env"] [unique_id "arQWYrPEMPPGwUGww4WgiAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-23 17:28:15
(4 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-23 17:20:13
(4 hours ago)
Excessive multi-domain requests
Brute-Force