๐ฉ๐ช
big-cloud.nl
2026-09-30 17:21:52
(6 hours ago)
Try to access /files../.env
Web App Attack
Anonymous
2026-09-30 16:53:16
(7 hours ago)
136.108.225.95 - - [01/Oct/2026:00:53:14 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozi ...
show more
136.108.225.95 - - [01/Oct/2026:00:53:14 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
136.108.225.95 - - [01/Oct/2026:00:53:15 +0800] "GET /build/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
136.108.225.95 - - [01/Oct/2026:00:53:15 +0800] "GET /dist/.vite/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
136.108.225.95 - - [01/Oct/2026:00:53:15 +0800] "GET /.vite/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"
136.108.225.95 - - [01/Oct/2026:00:53:15 +0800] "GET /__/firebase/init.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:48:14
(8 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:48:07.763954 2026] [security2:error] [pid 22246:tid 22246] [client 136.108.225.95:51310] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||autodiscover.pocketgod.info|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "autodiscover.pocketgod.info"] [uri "/api/fs/read"] [unique_id "ar0vN30q6ch3tvSAh7heDAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:05:25
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:05:21.127258 2026] [security2:error] [pid 25511:tid 25523] [client 136.108.225.95:42394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bhsclassof68.info"] [uri "/.htpasswd"] [unique_id "ar0XId0c_B2kDkayPQVlGwAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 13:40:03
(10 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-30 12:50:11
(11 hours ago)
136.108.225.95 - - [30/Sep/2026:13:50:10 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d ...
show more
136.108.225.95 - - [30/Sep/2026:13:50:10 +0100] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 994 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 12:13:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:13:13.093912 2026] [security2:error] [pid 7855:tid 7855] [client 136.108.225.95:60038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.solarfarms.info"] [uri "/files../.env"] [unique_id "arz82TILWVEYwIuubQ3FRAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-30 11:32:41
(12 hours ago)
2026/09/30 12:32:37 [error] 3532286#3532286: *1484804 access forbidden by rule, client: 136.108.225. ...
show more
2026/09/30 12:32:37 [error] 3532286#3532286: *1484804 access forbidden by rule, client: 136.108.225.95, server: [redacted], request: "GET /api/.env/public/.env HTTP/2.0", host: "wiki.betatechnologies.info"
2026/09/30 12:32:38 [error] 3532286#3532286: *1484790 access forbidden by rule, client: 136.108.225.95, server: [redacted], request: "GET /admin%2F.env HTTP/2.0", host: "wiki.betatechnologies.info"
2026/09/30 12:32:39 [error] 3532286#3532286: *1484790 access forbidden by rule, client: 136.108.225.95, server: [redacted], request: "GET /api%2F.env HTTP/2.0", host: "wiki.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:32:08
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:32:03.068713 2026] [security2:error] [pid 9892:tid 9892] [client 136.108.225.95:34174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.abon.com.hk"] [uri "/api/.env/public/.env"] [unique_id "arzzM6_sLTpMxd808mLODgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:01:00
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:00:56.344085 2026] [security2:error] [pid 1234:tid 1234] [client 136.108.225.95:59438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kiuchi.info"] [uri "/build../.env"] [unique_id "arzr6JCJVmoVPvrwlZ5aoQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 10:45:04
(13 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 10:37:02
(13 hours ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.108.225.95 - - [30/Sep/2026:12:36:48 +0200] "GET /static../.env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:23:04
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:22:56.604360 2026] [security2:error] [pid 13531:tid 13531] [client 136.108.225.95:46450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hiddenhistory.info"] [uri "/build../.env"] [unique_id "arzjALGt2RxK7sDO7XOGngAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 09:59:29
(14 hours ago)
apache-auth
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:46:48
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.225.95 (95.225.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:46:41.963472 2026] [security2:error] [pid 3499:tid 3499] [client 136.108.225.95:43140] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adona.info|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adona.info"] [uri "/elmah.axd"] [unique_id "arzagWhGDjwwktN9732AHwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack