๐ธ๐ฌ
WMK965
2026-09-18 17:38:04
(2 hours ago)
136.108.102.118 - - [19/Sep/2026:01:38:03 +0800] "GET /asset-manifest.json HTTP/2.0" 404 1424 "-" "M ...
show more
136.108.102.118 - - [19/Sep/2026:01:38:03 +0800] "GET /asset-manifest.json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-"
136.108.102.118 - - [19/Sep/2026:01:38:03 +0800] "GET /dist/manifest.json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-"
136.108.102.118 - - [19/Sep/2026:01:38:03 +0800] "GET /z9x8c7v6b5-debug-trigger-api.965server.top HTTP/2.0" 404 1424 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-"
136.108.102.118 - - [19/Sep/2026:01:38:03 +0800] "GET /manifest.json HTTP/2.0" 404 1424 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0" "-"
136.108.102.118 - - [19/Sep/2026:01:38:03 +0800] "GET /assets/manifest.json HTT
show less
Port Scan
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-18 16:55:06
(3 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 93 unauthorized requests recorded between 2026-09-17 16:49:46 UTC and 2026-09-17 16:49:58 UTC (rate: ~93 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 16:49:54 UTC] IP: 136.108.102.118 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 136.108.102.118]
[2026-09-17 16:49:54 UTC] IP: 136.108.102.118 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 136.108.102.118]
[2026-09-17 16:49:54 UTC] IP: 136.108.102.118 - W3C IIS (Port 443): GET /css../.env -> HTTP 404 [CLIENT: 136.108.102.118]
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-09-18 14:38:00
(5 hours ago)
HTTP DDoS Attack Layer 7
DDoS Attack
๐ฉ๐ช
rh24
2026-09-18 13:30:05
(6 hours ago)
Blacklisted for CAPTCHA_DOS_ALERT after 101 captcha requests
DDoS Attack
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-17 23:01:02
(20 hours ago)
Active Response: IP 136.108.102.118 Blocked via Firewall Drop, File/Directory scanning with suspicio ...
show more
Active Response: IP 136.108.102.118 Blocked via Firewall Drop, File/Directory scanning with suspicious user agent Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/).. Threat Score: 7.7/10 (HIGH). Confidence: 60%. CVSS v3.1: 7.3/10 (High). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 87%. MITRE ATT&CK: T1046 (Network Service Scanning). Tactic: TA0007. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-17 22:00:09
(21 hours ago)
File/Directory scanning with suspicious user agent Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +htt ...
show more
File/Directory scanning with suspicious user agent Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/).. Threat Score: 7.3/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฆ๐ช
CG
2026-09-17 21:51:03
(22 hours ago)
Web application attack, Automated scan
Web App Attack
Hacking
SQL Injection
๐ง๐ท
dermatovirtual
2026-09-17 16:53:52
(1 day ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 93 unauthorized requests recorded between 2026-09-17 16:49:46 UTC and 2026-09-17 16:49:58 UTC (rate: ~93 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 16:49:54 UTC] IP: 136.108.102.118 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 136.108.102.118]
[2026-09-17 16:49:54 UTC] IP: 136.108.102.118 - W3C IIS (Port 443): GET /.env -> HTTP 404 [CLIENT: 136.108.102.118]
[2026-09-17 16:49:54 UTC] IP: 136.108.102.118 - W3C IIS (Port 443): GET /css../.env -> HTTP 404 [CLIENT: 136.108.102.118]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-09-17 16:00:02
(1 day ago)
Excessive connections (DDoS/flood) blocked by CSF CT_LIMIT on wp1.
DDoS Attack
Brute-Force
๐ฉ๐ช
rh24
2026-09-17 13:30:05
(1 day ago)
Blacklisted for CAPTCHA_DOS_ALERT after 101 captcha requests
DDoS Attack
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-17 12:48:20
(1 day ago)
excessive HTTP 404 errors
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-17 11:18:23
(1 day ago)
[ti-24al] Excessive 404 errors (web scanning): 28 suspicious requests detected by fail2ban jail apac ...
show more
[ti-24al] Excessive 404 errors (web scanning): 28 suspicious requests detected by fail2ban jail apache-404. Example: 136.108.102.118 - - [17/Sep/2026:13:18:04 +0200] "GET /.zshrc HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
136.108.102.118 - - [17/Sep/2026:13:18:04 +0200] "GET /.bash_profile HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
136.108.102.118 - - [17/Sep/2026:13:18:04 +0200] "GET /.profile HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
136.108.102.118 - - [17/Sep/2026:13:18:04 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
136.108.102.118 - - [17/Sep
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 11:14:12
(1 day ago)
136.108.102.118 - - [17/Sep/2026:06:14:12 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
136.108.102.118 - - [17/Sep/2026:06:14:12 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 136.108.102.118
136.108.102.118 - - [17/Sep/2026:06:14:12 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 136.108.102.118
136.108.102.118 - - [17/Sep/2026:06:14:12 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 136.108.102.118
136.108.102.118 - - [17/Sep/2026:06:14:12 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 136.108.102.118
136.108.102.118 - - [17/Sep/2026:06:14:12 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 136.108.102.118
136.108.102.118 - - [17/Sep/2026:06:14:12 -0500]
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 11:13:34
(1 day ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐จ๐ฆ
Mediashaker
2026-09-17 10:41:35
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.108.102.118 (US/ ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.108.102.118 (US/United States/118.102.108.136.bc.googleusercontent.com)
show less
Bad Web Bot