๐ฌ๐ง
consul.to
2026-10-11 03:15:22
(57 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
FrankNeirynck
2026-10-11 00:00:29
(4 hours ago)
ailive.duckdns.org 136.108.249.166 - - [11/Oct/2026:02:00:27 +0200] "GET /.env HTTP/1.1" 404 134 "-" ...
show more
ailive.duckdns.org 136.108.249.166 - - [11/Oct/2026:02:00:27 +0200] "GET /.env HTTP/1.1" 404 134 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-AdsBot/1.0; +https://openai.com/adsbot" 0.000
ailive.duckdns.org 136.108.249.166 - - [11/Oct/2026:02:00:27 +0200] "GET /.env.example HTTP/1.1" 404 134 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 0.000
ailive.duckdns.org 136.108.249.166 - - [11/Oct/2026:02:00:27 +0200] "GET /.env.production HTTP/1.1" 404 134 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 0.000
ailive.duckdns.org 136.108.249.166 - - [11/Oct/2026:02:00:27 +0200] "GET /.env.local HTTP/1.1" 404 134 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 0.000
ailive.duckdns.org 136.108.249.166 - - [11/Oct/2026:02:00:27 +0200] "GET /.env.backup HTTP/1.1" 404 134 "-" "DuckAssistBot/1.1 (https://duckd
...
show less
Hacking
Web App Attack
๐ฌ๐ง
Apache
2026-10-10 23:56:25
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.249.166 (US/United States/166.249.108.1 ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.249.166 (US/United States/166.249.108.136.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
SSH
Web App Attack
๐บ๐ฆ
RatCommander
2026-10-10 23:52:27
(4 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files
Port Scan
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-10 23:21:49
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
melroy89
2026-10-10 23:14:29
(4 hours ago)
136.108.249.166 - - [11/Oct/2026:01:13:43 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows N ...
show more
136.108.249.166 - - [11/Oct/2026:01:13:43 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "admin.melroy.org" 0.000
136.108.249.166 - - [11/Oct/2026:01:13:43 +0200] "GET /f05n73ahi1gys41mouqh HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "admin.melroy.org" 0.000
136.108.249.166 - - [11/Oct/2026:01:13:43 +0200] "GET /z9x8c7v6b5-debug-trigger-admin.melroy.org HTTP/1.1" 403 9 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "admin.melroy.org" 0.000
136.108.249.166 - - [11/Oct/2026:01:13:44 +0200] "GET /ys6btm9w0fqnheax3y9i HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; Meta-ExternalFetcher/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "admin.melroy.org" 0.000
136.108.249.166 - - [11/Oct/2026:01:13:44 +0200] "POST /graphql HTTP/1.1" 403 9 "https://admin.melr
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:59:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.249.166 (166.249.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.249.166 (166.249.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:59:09.323789 2026] [security2:error] [pid 9698:tid 9698] [client 136.108.249.166:55932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admin.cmabiblequizzing.org"] [uri "/assets../.env"] [unique_id "asrDPbTrRPa4UqtZSkM3OAAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-10-10 22:15:10
(5 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 22:08:00
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.249.166 (166.249.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.249.166 (166.249.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:07:55.669833 2026] [security2:error] [pid 3467:tid 3467] [client 136.108.249.166:41398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "929.hongkonger.org"] [uri "/static//.env"] [unique_id "asq3O-j1HUDm-0VrjNO7uwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 21:37:01
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.249.166 (166.249.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.249.166 (166.249.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 17:36:53.361859 2026] [security2:error] [pid 27679:tid 27679] [client 136.108.249.166:48646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1derfulwaysrv.bknj2.org"] [uri "/assets../.env"] [unique_id "asqv9Sa6BrqhYl8X6E1X4wAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-10 20:01:52
(8 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-10-10T20:01:49.422257722Z. Context: http_status=404
show less
Web App Attack
๐ฉ๐ช
Blexyel
2026-10-10 19:59:33
(8 hours ago)
136.108.249.166 - - [10/Oct/2026:21:59:32 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5. ...
show more
136.108.249.166 - - [10/Oct/2026:21:59:32 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-10-10 19:50:08
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 19:42:33
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.249.166 (166.249.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.249.166 (166.249.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:42:28.019324 2026] [security2:error] [pid 30016:tid 30016] [client 136.108.249.166:60736] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelsabbey.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelsabbey.org"] [uri "/rclone.conf"] [unique_id "asqVJLuPOnPJdWtqUW6CdgAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 19:27:08
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.108.249.166 (166.249.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.249.166 (166.249.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:27:02.071905 2026] [security2:error] [pid 16905:tid 16979] [client 136.108.249.166:36688] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||killasgarage.bike|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "killasgarage.bike"] [uri "/rclone.conf"] [unique_id "asqRhplfjBi9KMaVKnF0SAAAAgk"]
show less
Brute-Force
Bad Web Bot
Web App Attack