๐บ๐ธ
[email protected]
2026-10-08 22:52:51
(2 days ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 30h39m18s)
Port Scan
๐บ๐ธ
[email protected]
2026-10-07 05:31:58
(3 days ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m59s)
Port Scan
๐ณ๐ฑ
Savvii
2026-10-07 00:39:54
(4 days ago)
20 attempts against mh-misbehave-ban on chive
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 00:07:15
(4 days ago)
Automated web scanner. Requested suspicious paths: /dist/manifest.json | /dist/.vite/manifest.json | ...
show more
Automated web scanner. Requested suspicious paths: /dist/manifest.json | /dist/.vite/manifest.json | /.vite/manifest.json | /build/manifest.json. UTC: 2026-10-06 23:39:55.
show less
Web App Attack
๐บ๐ธ
[email protected]
2026-10-06 23:56:38
(4 days ago)
CrowdSec ban: crowdsecurity/http-bad-user-agent (duration: 71h59m55s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:52:59
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 136.108.190.249 (249.190.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.190.249 (249.190.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:52:55.793386 2026] [security2:error] [pid 15272:tid 15272] [client 136.108.190.249:48768] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unified-dispatch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unified-dispatch.com"] [uri "/z9x8c7v6b5-debug-trigger-unified-dispatch.com"] [unique_id "asWJ1-mZXoevy4BnJHqp3gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tmiland
2026-10-06 23:41:30
(4 days ago)
Detected 63 connections from 136.108.190.249 last 10 minutes.; lone high-rate source (combined 126 r ...
show more
Detected 63 connections from 136.108.190.249 last 10 minutes.; lone high-rate source (combined 126 requests in both windows); Logs: 136.108.190.249 - - [07/Oct/2026:01:41:00 +0200] "GET / HTTP/1.1" 200 19730 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 136.108.190.249 - - [07/Oct/2026:01:41:00 +0200] "GET /static/manifest.json HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 136.108.190.249 - - [07/Oct/2026:01:41:00 +0200] "GET /asset-manifest.json HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 136.108.190.249 - - [07/Oct/2026:01:41:01 +0200] "GET /manifest.json HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 136.108.190.249 - -
show less
DDoS Attack
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tmiland
2026-10-06 23:41:09
(4 days ago)
(nginx_444) Nginx 444 136.108.190.249 (US/United States/249.190.108.136.bc.googleusercontent.com): 5 ...
show more
(nginx_444) Nginx 444 136.108.190.249 (US/United States/249.190.108.136.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 136.108.190.249; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.108.190.249 - - [07/Oct/2026:01:41:03 +0200] "GET /wp-json HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 136.108.190.249 - - [07/Oct/2026:01:41:03 +0200] "GET /wp-json HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 136.108.190.249 - - [07/Oct/2026:01:41:03 +0200] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 136.108.190.249 - - [07/Oct/2026:01:41:03 +0200] "GET /.ssh/id_rsa HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 136.108.190.249 - - [07/Oct/2026:01:41:0
show less
Brute-Force
Anonymous
2026-10-06 23:40:03
(4 days ago)
suspicious request in access.log
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-10-06 23:38:36
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 136.108.190.249 (US/United States/249.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.108.190.249 (US/United States/249.190.108.136.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
LRob
2026-10-06 23:28:51
(4 days ago)
Secret file probe | method: GET | path: /.npmrc, /.htpasswd, /.ssh/id_rsa (+9 more) | ua: Mozilla/5. ...
show more
Secret file probe | method: GET | path: /.npmrc, /.htpasswd, /.ssh/id_rsa (+9 more) | ua: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot), DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot), Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot (+9 more)
show less
Hacking
Web App Attack
๐บ๐ธ
ambor
2026-10-06 23:11:43
(4 days ago)
Honeypot triggered on tcpdata.com - Attempted to access /.vite/manifest.json (hidden_file_probe). Us ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /.vite/manifest.json (hidden_file_probe). User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36
show less
Web App Attack
๐ง๐ท
radardatelecom
2026-10-06 22:27:02
(4 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ซ๐ท
raid3n09
2026-10-06 22:12:49
(4 days ago)
Automated malicious scan and unauthorized access attempt blocked.
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-10-06 21:11:06
(4 days ago)
(mod_security) mod_security (id:11000011) triggered by 136.108.190.249 (US/United States/South Carol ...
show more
(mod_security) mod_security (id:11000011) triggered by 136.108.190.249 (US/United States/South Carolina/North Charleston/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Oct 07 00:11:01.306856 2026] [security2:error] [pid 1054755:tid 1054762] [remote 136.108.190.249:32784] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 249.190.108.136.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "tavernadimitris.com"] [uri "/"] [unique_id "asVj5QPbd9HNUUbo3qclGAAAUAY"]
show less
Port Scan