This IP address has been reported a total of
138
times from
84 distinct
sources.
136.108.89.82 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[FriAug2805:07:37.4247462026][security2:error][pid3768221:tid3768401][client136.108.89.82:0]ModSecur ...
show more[FriAug2805:07:37.4247462026][security2:error][pid3768221:tid3768401][client136.108.89.82:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.labaita-lanzo.it\"][uri\"/@fs/home/ubuntu/.aws/credentials\"][unique_id\"apD7eXgHui1dux_jajM1WAAAAFA\"]
show less
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show moreInbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 136.108.89.82 (US/United States/82.8 ...
show moreLF_MODSEC: (mod_security) mod_security (id:949110) triggered by 136.108.89.82 (US/United States/82.89.108.136.bc.googleusercontent.com): 1 in the last 3600 secs
show less
(mod_security) mod_security (id:949110) triggered by 136.108.89.82 (US/United States/82.89.108.136.b ...
show more(mod_security) mod_security (id:949110) triggered by 136.108.89.82 (US/United States/82.89.108.136.bc.googleusercontent.com): 5 in the last 600 secs; ID: rub
show less
Automated report (2026-08-26T23:09:08+08:00). Scraper detected. User agent regularly (and almost exc ...
show moreAutomated report (2026-08-26T23:09:08+08:00). Scraper detected. User agent regularly (and almost exclusively) cited by requests for sensitive files, vulnerable/exploitable endpoints, during brute-force attacks, and hack attempts.
show less
[WedAug2613:18:39.2714412026][security2:error][pid3847788:tid3847893][client136.108.89.82:0]ModSecur ...
show more[WedAug2613:18:39.2714412026][security2:error][pid3847788:tid3847893][client136.108.89.82:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"modularss.com\"][uri\"/@fs/var/task/.env\"][unique_id\"ao7Lj-HksNlY5CJUaA19qAAAANA\"]
show less