๐ฏ๐ต
ki3
2026-08-20 12:53:20
(1 minute ago)
Fail2Ban: Web App Attacks and Forum Spam 136.108.32.144 1787230399.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-20 12:50:06
(4 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-08-20 12:47:57
(6 minutes ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-20 12:39:33
(14 minutes ago)
136.108.32.144 - - [20/Aug/2026:14:39:31 +0200] "GET /.codex/config.toml HTTP/2.0" 404 293 "-" "Mozi ...
show more
136.108.32.144 - - [20/Aug/2026:14:39:31 +0200] "GET /.codex/config.toml HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email]"
136.108.32.144 - - [20/Aug/2026:14:39:31 +0200] "GET /service_account.json HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email]"
136.108.32.144 - - [20/Aug/2026:14:39:31 +0200] "GET /.hermes/auth.json HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email]"
136.108.32.144 - - [20/Aug/2026:14:39:31 +0200] "GET /Dockerfile HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email]"
136.108.32.144 - - [20/Aug/2026:14:39:31 +0200] "GET /service-worker.js HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email]"
136.108.32.144 - - [20/Aug/2026:14:39:31 +0200]
show less
Bad Web Bot
Anonymous
2026-08-20 12:27:23
(27 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-08-20 12:06:45
(47 minutes ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-08-20 12:06:39
(47 minutes ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-20 12:03:58
(50 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.108.32.144 (144.32.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.32.144 (144.32.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 08:03:50.995224 2026] [security2:error] [pid 9528:tid 9593] [client 136.108.32.144:37528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.geekshop.com|F|2"] [data ".geekshop.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.geekshop.com"] [uri "/z9x8c7v6b5-debug-trigger-ftp.geekshop.com"] [unique_id "aobtJrs2a_UgGS-RMNbcqAAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-20 12:02:43
(51 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฏ๐ต
ki3
2026-08-20 11:52:19
(1 hour ago)
Fail2Ban: Web App Attacks and Forum Spam 136.108.32.144 1787226738.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 11:42:53
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 136.108.32.144 (144.32.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.32.144 (144.32.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 07:42:45.435977 2026] [security2:error] [pid 3383:tid 3383] [client 136.108.32.144:45734] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gdg1.bizecomm.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gdg1.bizecomm.com"] [uri "/rclone.conf"] [unique_id "aoboNZEogjSr7WU-qYBC9wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 11:25:15
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.108.32.144 (144.32.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.32.144 (144.32.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 07:25:10.370538 2026] [security2:error] [pid 8294:tid 8294] [client 136.108.32.144:53310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sophcomp.com"] [uri "/.git/config"] [unique_id "aobkFthMEuI5yGC1f-6FfgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-20 11:17:02
(1 hour ago)
(modsecurity) srv102 ModSecurity 136.108.32.144 (US/United States/144.32.108.136.bc.googleuserconten ...
show more
(modsecurity) srv102 ModSecurity 136.108.32.144 (US/United States/144.32.108.136.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
factor1
2026-08-20 11:16:00
(1 hour ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐ฉ๐ช
Viveronese
2026-08-20 11:04:35
(1 hour ago)
HTTP vulnerability scanning
Web App Attack