Anonymous
2026-09-07 13:45:04
(5 hours ago)
Observed scanned 17 known-sensitive endpoint(s), e.g.: /.bash_profile, /.env.prod.bak, /.github/work ...
show more
Observed scanned 17 known-sensitive endpoint(s), e.g.: /.bash_profile, /.env.prod.bak, /.github/workflows/deploy.yml, /.svn/entries, /@fs/.env, /@fs/home/ubuntu/.oci/config
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 03:32:59
(15 hours ago)
136.108.19.238 - - [06/Sep/2026:05:51:58 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla ...
show more
136.108.19.238 - - [06/Sep/2026:05:51:58 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" 136.108.19.238
136.108.19.238 - - [06/Sep/2026:05:51:58 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" 136.108.19.238
136.108.19.238 - - [06/Sep/2026:05:51:58 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" 136.108.19.238
136.108.19.238 - - [06/Sep/2026:05:51:58 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" 136.108.19.238
136.108.19.238 - - [06/Sep/2026:05:51:58 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
slay3r9903
2026-09-07 01:47:10
(17 hours ago)
Wazuh rule 100308: NPM sensitive-path storm: rule 100304 ≥5 times in 10s from same IP
Brute-Force
Port Scan
🇺🇸
mnsf
2026-09-07 00:05:15
(19 hours ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
🇵🇱
Niko's Stuff
2026-09-06 23:00:26
(20 hours ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/136.108.19.2 ...
show more
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/136.108.19.238
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 21:17:12
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.19.238 (238.19.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.19.238 (238.19.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:17:06.824749 2026] [security2:error] [pid 25060:tid 25060] [client 136.108.19.238:53726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leadslibrary.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leadslibrary.net"] [uri "/privatekey.key"] [unique_id "ap3YUsFLqKXIEKUQfN_tYgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
kranem
2026-09-06 21:00:29
(22 hours ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.aws/config
Timestamp: 2026-09-06T20:19:33Z
User-Agent: Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)
show less
Bad Web Bot
Anonymous
2026-09-06 20:27:12
(22 hours ago)
Portscan: TCP/8443 (4x), TCP/8080 (4x), TCP/443
Port Scan
🇬🇧
consul.to
2026-09-06 19:40:47
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇪🇸
el-brujo
2026-09-06 19:26:01
(23 hours ago)
136.108.19.238 - - [06/Sep/2026:21:26:01 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0 ...
show more
136.108.19.238 - - [06/Sep/2026:21:26:01 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15886 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
136.108.19.238 - - [06/Sep/2026:21:26:01 +0200] "GET /rclone.conf HTTP/2.0" 404 15886 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
136.108.19.238 - - [06/Sep/2026:21:26:01 +0200] "GET /.vscode/launch.json HTTP/2.0" 404 15886 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
136.108.19.238 - - [06/Sep/2026:21:26:01 +0200] "GET /build/manifest.json HTTP/2.0" 404 15886 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
...
show less
Web App Attack
Hacking
Anonymous
2026-09-06 18:24:31
(1 day ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /secrets.env
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 16:45:20
(1 day ago)
137 requests with url.path *.ssh/*
111 requests with url.path *.oci/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 15:15:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.108.19.238 (238.19.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.19.238 (238.19.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:15:26.050800 2026] [security2:error] [pid 9677:tid 9677] [client 136.108.19.238:34054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vabq.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vabq.com"] [uri "/rclone.conf"] [unique_id "ap2DjkWAd__mP5QTtiejIQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
csnavarro2020
2026-09-06 14:55:13
(1 day ago)
Automated scan for known vulnerable/nonexistent path: /.aws/config
Web App Attack
Hacking
🇺🇸
slay3r9903
2026-09-06 13:26:48
(1 day ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot