๐บ๐ธ
kosada.com
2026-09-01 14:56:43
(5 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /.env (bogus vhost/SNI) (HTTP port 8 ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.env (bogus vhost/SNI) (HTTP port 80)
show less
Web App Attack
๐ซ๐ท
โจ
2026-09-01 08:53:07
(11 hours ago)
Domain : pleskcontrolpanel
Rule : config
2026-09-01 08:51:48 ***hidden-privacy*** GET /.git/config - ...
show more
Domain : pleskcontrolpanel
Rule : config
2026-09-01 08:51:48 ***hidden-privacy*** GET /.git/config - 8443 - 136.108.62.220 Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; https://openai.com/gptbot) Chrome/151.0.961.33 Mobile Safari/537.36 - 404 8 0 1216 371 112 - -
show less
Hacking
SQL Injection
๐ง๐ท
SOC-BR
2026-09-01 07:27:03
(13 hours ago)
Attack detected by Fortinet - web_server: HTTP.Request.URI.Path.Traversal - 2026-08-31 08:18:11 - So ...
show more
Attack detected by Fortinet - web_server: HTTP.Request.URI.Path.Traversal - 2026-08-31 08:18:11 - Source Port 63692
show less
Port Scan
Hacking
Anonymous
2026-09-01 05:49:28
(14 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.108.62.220 (US/United States/220.62.108. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.108.62.220 (US/United States/220.62.108.136.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.108.62.220 - - [01/Sep/2026:07:49:26 +0200] "GET /@fs/../.env?raw?? HTTP/1.1" 406 991 "-" "Mozilla/5.0 (compatible; ClaudeBot/1.0; [email protected] )"
136.108.62.220 - - [01/Sep/2026:07:49:27 +0200] "GET /.env HTTP/1.1" 406 991 "-" "Mozilla/5.0 (Windows NT 10.0; rv:150.17) Gecko/20100101 Firefox/150.17; compatible; GrokBot/1.0; +https://x.ai/grokbot"
136.108.62.220 - - [01/Sep/2026:07:49:27 +0200] "GET /app/.env HTTP/1.1" 406 991 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; LinkedInBot/1.0; +http://www.linkedin.com"
show less
Port Scan
๐น๐ญ
Sawasdee
2026-09-01 01:15:08
(19 hours ago)
Port Scan
...
Port Scan
๐ซ๐ท
Catalin Negru
2026-09-01 00:18:52
(20 hours ago)
2026-09-01 03:18:47,679 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 136.108.62.220
2 ...
show more
2026-09-01 03:18:47,679 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 136.108.62.220
2026-09-01 03:18:48,059 fail2ban.actions [1796604]: NOTICE [apache-scan] Ban 136.108.62.220
2026-09-01 03:18:48,059 fail2ban.actions [1796604]: NOTICE [apache-security] Ban 136.108.62.220
2026-09-01 03:18:48,075 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 136.108.62.220
2026-09-01 03:18:48,259 fail2ban.actions [1796604]: NOTICE [apache-dirscan] Ban 136.108.62.220
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
JustMeHere
2026-08-31 23:50:56
(20 hours ago)
[Mon Aug 31 19:50:50.946987 2026] [security2:error] [pid 43395:tid 43545] [client 136.108.62.220:531 ...
show more
[Mon Aug 31 19:50:50.946987 2026] [security2:error] [pid 43395:tid 43545] [client 136.108.62.220:53108] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "73.88.79.72"] [uri "/static../.env"] [unique_id "apYTWuDrgMTjxsoWwmnwRgAAABQ"]
...
show less
Web App Attack
๐ต๐ฑ
webadmin
2026-08-31 15:28:31
(1 day ago)
2026-08-31T17:28:27.786506+02:00 tytan csmpro-api[3056]: [error] client: 136.108.62.220 server: 195. ...
show more
2026-08-31T17:28:27.786506+02:00 tytan csmpro-api[3056]: [error] client: 136.108.62.220 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/ [404]: Not Found
2026-08-31T17:28:28.787092+02:00 tytan csmpro-api[3056]: [error] client: 136.108.62.220 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/__aws_leak_probe_8dc4f953__ [404]: Not Found
2026-08-31T17:28:30.419096+02:00 tytan csmpro-api[3056]: [error] client: 136.108.62.220 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/static../.env [404]: Not Found
2026-08-31T17:28:30.419096+02:00 tytan csmpro-api[3056]: [error] client: 136.108.62.220 server: 195.116.29.58, request: "GET", url: http://195.116.29.58/static../etc/passwd [404]: Not Found
show less
Web App Attack
๐บ๐ธ
Armin Resch
2026-08-31 11:56:00
(1 day ago)
Rule: 31153 fired (level 10) -> "Multiple common web attacks from same source ip."
Web App Attack
๐ต๐ฑ
dcnet
2026-08-31 06:00:06
(1 day ago)
FortiGate detected DOS attack from IPv4 address 136.108.62.220
DDoS Attack
๐ณ๐ฟ
Antinson
2026-08-31 02:28:10
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐น๐ผ
kk_it_man
2026-08-31 00:33:01
(1 day ago)
ET INFO ChatGPT-User Traffic Detected Inbound M1
ET INFO ChatGPT-User Traffic Detected Inbound M2 ...
show more
ET INFO ChatGPT-User Traffic Detected Inbound M1
ET INFO ChatGPT-User Traffic Detected Inbound M2
ET INFO Request for Visual Studio Code sftp.json - Possible Information Leak
ET INFO Request to Hidden Environment File - Inbound
ET SCAN SFTP/FTP Password Exposure via sftp-config.json
ET WEB_SERVER .bash_history Detected in URI
ET WEB_SERVER /etc/passwd Detected in URI
ET WEB_SERVER Likely Malicious Request for /proc/self/environ
ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
ET WEB_SERVER WEB-PHP phpinfo access
ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208)
ET WEB_SPECIFIC_APPS Wordpress LiteSpeed Cache Plugin debug.log Access Attempt (CVE-2024-44000)
GPL WEB_SERVER 403 Forbidden
show less
Port Scan
๐ฉ๐ช
paprika
2026-08-30 04:46:44
(2 days ago)
Automated report #1: 314 attacks detected. Types: Path Traversal, File Inclusion, Brute-force (login ...
show more
Automated report #1: 314 attacks detected. Types: Path Traversal, File Inclusion, Brute-force (login).
show less
Brute-Force
Email Spam
Hacking
๐ซ๐ท
ingroscart.it
2026-08-30 02:12:48
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
IndigoRidge
2026-08-30 00:21:41
(2 days ago)
Knock-Knock HTTP honeypot activity; time=2026-08-30 00:19:16; http_method=GET; http_path=/; http_pur ...
show more
Knock-Knock HTTP honeypot activity; time=2026-08-30 00:19:16; http_method=GET; http_path=/; http_purpose=basic_probe; http_user_agent=Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.7786.22
show less
Web App Attack