๐ณ๐ฑ
Alt255
2026-09-15 15:06:46
(23 hours ago)
[ti-01ov] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail <nam ...
show more
[ti-01ov] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail <name>. Example: 136.108.71.254 - - \[13/Sep/2026:15:56:20 +0200\] "GET /.git/config HTTP/1.1" 404 2101 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Perplexity-User/1.0\; +https://perplexity.ai/perplexitybot\)"
136.108.71.254 - - \[13/Sep/2026:15:56:20 +0200\] "GET /z9x8c7v6b5-debug-trigger-imoos.org HTTP/1.1" 404 2101 "-" "Mozilla/5.0 \(compatible\; Googlebot/2.1\; +http://www.google.com/bot.html\)"
136.108.71.254 - - \[13/Sep/2026:15:56:20 +0200\] "GET /.env HTTP/1.1" 404 2101 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/605.1.15 \(KHTML, like Gecko\) Version/17.0 Safari/605.1.15 \(Applebot/0.1\)"
136.108.71.254 - - \[13/Sep/2026:15:56:20 +0200\] "GET /.aws/credentials HTTP/1.1" 404 7420 "-" "Mozilla/
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 00:00:24
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.108.71.254 (254.71.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.71.254 (254.71.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 20:00:18.865709 2026] [security2:error] [pid 28935:tid 28935] [client 136.108.71.254:52322] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wisk.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wisk.org"] [uri "/rclone.conf"] [unique_id "aqc5EkXGeFVYSNgM7W7n2gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 23:43:15
(2 days ago)
136.108.71.254 - - [13/Sep/2026:18:43:13 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" " ...
show more
136.108.71.254 - - [13/Sep/2026:18:43:13 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 136.108.71.254
136.108.71.254 - - [13/Sep/2026:18:43:13 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 136.108.71.254
136.108.71.254 - - [13/Sep/2026:18:43:13 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 136.108.71.254
136.108.71.254 - - [13/Sep/2026:18:43:13 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 136.108.71.254
136.108.71.254 - - [13/Sep/2026:18:43:13 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 136.108.71.254
136.108.71.254 - - [13/Sep/2026:18:43:13 -0500] "GET /.env.development?raw HTTP/1.1" 403 1
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 23:22:55
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.108.71.254 (254.71.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.108.71.254 (254.71.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 19:22:50.049559 2026] [security2:error] [pid 8886:tid 8886] [client 136.108.71.254:57504] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||newlifeworshipcentre-gc.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "newlifeworshipcentre-gc.org"] [uri "/rclone.conf"] [unique_id "aqcwSileRFhGgUGz8hRr9gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 22:56:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.108.71.254 (254.71.108.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.71.254 (254.71.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:56:33.947765 2026] [security2:error] [pid 26872:tid 26872] [client 136.108.71.254:37056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalpozzolanassociation.org"] [uri "/@fs/.env"] [unique_id "aqcqIc5jJkK4WBDRtpA01QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 22:54:38
(2 days ago)
136.108.71.254 - - [14/Sep/2026:00:54:37 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; An ...
show more
136.108.71.254 - - [14/Sep/2026:00:54:37 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36 EdgA/151.0.0.0"
136.108.71.254 - - [14/Sep/2026:00:54:37 +0200] "GET /z9x8c7v6b5-debug-trigger-natorin.org HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
136.108.71.254 - - [14/Sep/2026:00:54:37 +0200] "GET /@fs/.env?url&raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
136.108.71.254 - - [14/Sep/2026:00:54:37 +0200] "GET /rclone.conf HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
136.108.71.254 - - [14/Sep/2026:00:54:37 +0200] "GET /@fs/.env?raw&url?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.108.71.254 - - [14/Sep/2026:00:54:37 +0200] "GET /account HTTP/1.1" 403 183 "-" "Mozilla/5.0 (
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-13 22:04:22
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-13 21:48:47
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.108.71.254 (US/U ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.108.71.254 (US/United States/254.71.108.136.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฉ๐ช
ger-stg-sifi1
2026-09-13 21:31:27
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
dot.mg
2026-09-13 21:05:10
(2 days ago)
Bad behaviour
Web Spam
๐บ๐ธ
Major Hostility
2026-09-13 20:50:06
(2 days ago)
"GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404
"GET /.vite/mani ...
show more
"GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404
"GET /.vite/manifest.json HTTP/1.1" 404
"GET /login HTTP/1.1" 404
"GET /sign-in HTTP/1.1" 404
"GET /rclone.conf HTTP/1.1" 404
"GET /z9x8c7v6b5-debug-trigger-[DOMAIN].org HTTP/1.1" 404
"GET /user/login HTTP/1.1" 404
"POST /graphql HTTP/1.1" 404
"GET /signup HTTP/1.1" 404
"POST /api/graphql HTTP/1.1" 404
"GET /register HTTP/1.1" 404
"GET /forgot-password HTTP/1.1" 404
"POST /v1/graphql HTTP/1.1" 404
"GET /admin HTTP/1.1" 404
"GET /reset-password HTTP/1.1" 404
"GET /dashboard HTTP/1.1" 404
"GET /admin/login HTTP/1.1" 404
"GET /backoffice HTTP/1.1" 404
"GET /console HTTP/1.1"%2
show less
Web App Attack
๐ฉ๐ช
Melle
2026-09-13 20:40:01
(2 days ago)
Unauthorized connection attempt detected from IP address 136.108.71.254
Bad Web Bot
๐จ๐ญ
zynex
2026-09-13 20:36:25
(2 days ago)
URL Probing: /backend/.env
Web App Attack
๐ฉ๐ช
konseptit
2026-09-13 20:35:06
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 136.108.71.254 (US/United States/254.71 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.108.71.254 (US/United States/254.71.108.136.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
mnsf
2026-09-13 20:05:16
(2 days ago)
Scanning/Probing (19)
Brute-Force
Web App Attack