๐ฌ๐ง
Marten Mark
2026-08-15 01:46:14
(1 month ago)
136.109.167.91 - - [15/Aug/2026:01:46:07 +0000] "GET /.aws/credentials HTTP/2.0" 404 23033 "https:// ...
show more
136.109.167.91 - - [15/Aug/2026:01:46:07 +0000] "GET /.aws/credentials HTTP/2.0" 404 23033 "https://www.cfi.co/.aws/credentials" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
136.109.167.91 - - [15/Aug/2026:01:46:07 +0000] "GET /.aws/config HTTP/2.0" 404 23033 "https://www.cfi.co/.aws/config" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
136.109.167.91 - - [15/Aug/2026:01:46:08 +0000] "GET /z9x8c7v6b5-debug-trigger-www.cfi.co HTTP/2.0" 404 23033 "https://www.cfi.co/z9x8c7v6b5-debug-trigger-www.cfi.co" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
136.109.167.91 - - [15/Aug/2026:01:46:08 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 404 23033 "https://www.cfi.co/dist/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
136.109.167.91 - - [15/Aug/2026:01:46:08 +0000] "GET /dist/manifest.json HTTP/2.0" 404 23033 "https://www.cfi.co/dist/manif
...
show less
Port Scan
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-15 01:45:01
(1 month ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-15 00:04:42
(1 month ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-14 23:45:00
(1 month ago)
Hacker trying relentlessly to access a WP site. Have blocked at least 20 IP addresses and ranges.
Brute-Force
Web App Attack
๐ฉ๐ช
NewGastroline
2026-08-14 23:31:53
(1 month ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
๐ฌ๐ง
Marten Mark
2026-08-14 22:02:27
(1 month ago)
136.109.167.91 - - [14/Aug/2026:22:02:26 +0000] "GET /.aws/credentials HTTP/2.0" 401 176 "-" "Mozill ...
show more
136.109.167.91 - - [14/Aug/2026:22:02:26 +0000] "GET /.aws/credentials HTTP/2.0" 401 176 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-14 13:06:37
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 136.109.167.91 (91.167.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.109.167.91 (91.167.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 09:06:32.546979 2026] [security2:error] [pid 4042:tid 4042] [client 136.109.167.91:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chaitanyaconsult.in|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chaitanyaconsult.in"] [uri "/rclone.conf"] [unique_id "an8S2GTSW0j43PpaeIuM0wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-14 12:30:09
(1 month ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 300 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐บ๐ธ
jormaster3k
2026-08-14 11:57:05
(1 month ago)
Attack against Apache (too many 404s)
Web App Attack
๐จ๐ฟ
antihack.anarchista.xyz
2026-08-14 10:06:34
(1 month ago)
404 burst: 20 hits in 5 min, URI /settings, Ref , UA Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) ...
show more
404 burst: 20 hits in 5 min, URI /settings, Ref , UA Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
show less
Brute-Force
Web App Attack
Bad Web Bot
๐จ๐ญ
4server
2026-08-14 09:50:12
(1 month ago)
[FriAug1411:50:06.6222732026][security2:error][pid1499109:tid1499313][client136.109.167.91:0]ModSecu ...
show more
[FriAug1411:50:06.6222732026][security2:error][pid1499109:tid1499313][client136.109.167.91:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ch-garantie.ch\"][uri\"/.aws/credentials\"][unique_id\"an7kzs4B3jIsb24CPWDo0gAAAIQ\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
klaus_ph
2026-08-14 09:29:59
(1 month ago)
...
Bad Web Bot
๐จ๐ฆ
polycoda
2026-08-14 08:44:27
(1 month ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-08-14 08:29:02
(1 month ago)
[14/Aug/2026:10:28:56.258070 +0200] an7RyDGiFYQ_JT2nX8cBUAAAAAg 136.109.167.91 49636 127.0.0.1 7081
...
show more
[14/Aug/2026:10:28:56.258070 +0200] an7RyDGiFYQ_JT2nX8cBUAAAAAg 136.109.167.91 49636 127.0.0.1 7081
[14/Aug/2026:10:28:56.373429 +0200] an7RyPLNOgq8Q7nOZnuYSgAAAAM 136.109.167.91 49696 127.0.0.1 7081
[14/Aug/2026:10:28:56.937258 +0200] an7RyLiSlVb-sZHI0tV7zgAAAAU 136.109.167.91 49710 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-08-14 08:28:34
(1 month ago)
136.109.167.91 - - [14/Aug/2026:08:28:33 +0000] "GET /dashboard HTTP/1.1" 404 196 "-" "Mozilla/5.0 ( ...
show more
136.109.167.91 - - [14/Aug/2026:08:28:33 +0000] "GET /dashboard HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.109.167.91 - - [14/Aug/2026:08:28:33 +0000] "GET /z9x8c7v6b5-debug-trigger-chirila.me HTTP/1.1" 404 134 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
...
show less
Web App Attack