๐ง๐ท
Peregrine
2026-10-11 03:16:52
(11 hours ago)
Fail2Ban Jail:IU tomcat-honeypot | Evidence: 136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 ...
show more
Fail2Ban Jail:IU tomcat-honeypot | Evidence: 136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 -0300] "GET /cache/original/%2e%2e/.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles?path=../../.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles?path=../../../.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /api/system/fileView?file=/app/.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles?path=../../../../.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles/x?path=../../.env HTTP/1.1" 404 -
show less
Bad Web Bot
๐ง๐ท
Peregrine
2026-10-10 03:16:51
(1 day ago)
Fail2Ban Jail:IU tomcat-honeypot | Evidence: 136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 ...
show more
Fail2Ban Jail:IU tomcat-honeypot | Evidence: 136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 -0300] "GET /cache/original/%2e%2e/.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles?path=../../.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles?path=../../../.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.226 - - [08/Oct/2026:21:07:48 -0300] "GET /api/system/fileView?file=/app/.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles?path=../../../../.env HTTP/1.1" 404 -
136.109.29.252 162.158.41.227 - - [08/Oct/2026:21:07:48 -0300] "GET /userfiles/x?path=../../.env HTTP/1.1" 404 -
show less
Bad Web Bot
๐ซ๐ท
IRISIO
2026-10-09 07:16:38
(2 days ago)
scans/SQL injection/spam posts : 68 queries
Web App Attack
SQL Injection
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-09 02:45:00
(2 days ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐จ๐ฟ
ptlab
2026-10-09 02:40:04
(2 days ago)
Web attack probes: 97 suspicious URL paths (84 known-malicious), 100 requests; 6 successful (2xx) re ...
show more
Web attack probes: 97 suspicious URL paths (84 known-malicious), 100 requests; 6 successful (2xx) requests to attack paths; types: admin-panel, cgi, lfi, rce, sensitive-files, traversal, wordpress; last seen 2026-10-09 (UTC). Reported automatically by PathDB log analysis.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:32:09
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.109.29.252 (252.29.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.109.29.252 (252.29.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:32:05.654573 2026] [security2:error] [pid 15790:tid 15790] [client 136.109.29.252:60624] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tremulant.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tremulant.com"] [uri "/z9x8c7v6b5-debug-trigger-tremulant.com"] [unique_id "ashSJf1vldOG3HbBo7tnuQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-10-09 02:09:14
(2 days ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐ฉ๐ช
snhosting
2026-10-09 02:02:40
(2 days ago)
136.109.29.252 - - [09/Oct/2026:04:02:30 +0200] "POST / HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible ...
show more
136.109.29.252 - - [09/Oct/2026:04:02:30 +0200] "POST / HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.109.29.252 - - [09/Oct/2026:04:02:30 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.109.29.252 - - [09/Oct/2026:04:02:30 +0200] "GET /z9x8c7v6b5-debug-trigger-snsolution.de HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
136.109.29.252 - - [09/Oct/2026:04:02:30 +0200] "GET /dist/manifest.json HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.109.29.252 - - [09/Oct/2026:04:02:30 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-09 01:58:29
(2 days ago)
2026/10/09 02:58:27 [error] 4060693#4060693: *1382304 access forbidden by rule, client: 136.109.29.2 ...
show more
2026/10/09 02:58:27 [error] 4060693#4060693: *1382304 access forbidden by rule, client: 136.109.29.252, server: simetria.org, request: "GET /static../.env HTTP/2.0", host: "simetria.org"
2026/10/09 02:58:27 [error] 4060693#4060693: *1382305 access forbidden by rule, client: 136.109.29.252, server: simetria.org, request: "GET /media../.env HTTP/2.0", host: "simetria.org"
2026/10/09 02:58:27 [error] 4060693#4060693: *1382306 access forbidden by rule, client: 136.109.29.252, server: simetria.org, request: "GET /files../.env HTTP/2.0", host: "simetria.org"
show less
Brute-Force
Web App Attack
Anonymous
2026-10-09 01:43:19
(2 days ago)
Blocked by fail2ban on a public web server.
Web App Attack
๐ฌ๐ง
rakkor
2026-10-09 01:34:51
(2 days ago)
2026-10-09T02:34:51+01:00 NAS [Fri Oct 09 02:34:51.427377 2026] [authz_core:error] [pid 1306:tid 132 ...
show more
2026-10-09T02:34:51+01:00 NAS [Fri Oct 09 02:34:51.427377 2026] [authz_core:error] [pid 1306:tid 1327] [client 136.109.29.252:58052] AH01630: client denied by server configuration: /var/services/web/.htpasswd
...
show less
Brute-Force
Hacking
๐ง๐ช
voormedia
2026-10-09 01:12:21
(2 days ago)
Accessed trap at '/.env'
Web App Attack
๐ซ๐ท
LoneRider
2026-10-09 01:03:07
(2 days ago)
[09/Oct/2026:03:03:06.313376 +0200] asg9Sv0Rv5Ui3LzPPiEbYAAAAAM 136.109.29.252 43580 127.0.0.1 7081
...
show more
[09/Oct/2026:03:03:06.313376 +0200] asg9Sv0Rv5Ui3LzPPiEbYAAAAAM 136.109.29.252 43580 127.0.0.1 7081
[09/Oct/2026:03:03:07.195961 +0200] asg9SyPvDwWEdO-X2ljRkwAAAAg 136.109.29.252 43874 127.0.0.1 7081
[09/Oct/2026:03:03:07.496418 +0200] asg9S8PtvAJ9KpWwpdULdAAAAAQ 136.109.29.252 43922 127.0.0.1 7081
...
show less
Hacking
๐ณ๐ฟ
realstuffie
2026-10-09 00:53:52
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ง๐พ
lns.bz
2026-10-09 00:39:35
(2 days ago)
Too many 404 requests [BY]
Web App Attack