๐ซ๐ท
SpaceHost-Server
2026-09-22 22:17:05
(5 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:54:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:54:52.039261 2026] [security2:error] [pid 5639:tid 5639] [client 136.109.71.159:35728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laecovillage.org"] [uri "/.env.old"] [unique_id "arHf7KZjIlYSu28Q1mYIWAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kbeezie
2026-09-22 01:39:44
(1 day ago)
136.109.71.159 - - [21/Sep/2026:21:39:43 -0400] "GET /api/w/default/jobs_u/get_log_file/../../../../ ...
show more
136.109.71.159 - - [21/Sep/2026:21:39:43 -0400] "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.109.71.159 - - [21/Sep/2026:21:39:43 -0400] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 429 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
136.109.71.159 - - [21/Sep/2026:21:39:44 -0400] "GET /env.old HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
136.109.71.159 - - [21/Sep/2026:21:39:44 -0400] "GET /_payload.json HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
136.109.71.159 - - [21/Sep/2026:21:39:44 -0400] "GET /dashboard/_payload.json HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:23:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:23:44.145103 2026] [security2:error] [pid 27924:tid 27939] [client 136.109.71.159:57646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ahsdistance.org"] [uri "/.env.production"] [unique_id "arG8gM2yxpXeo1xwdH3OPwAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:32:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:32:06.131088 2026] [security2:error] [pid 19617:tid 19617] [client 136.109.71.159:52018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "todi.org"] [uri "/.git/HEAD"] [unique_id "arGwZoV1VbsAO01YdFKOTgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Sonoflet
2026-09-21 22:27:32
(1 day ago)
CrowdSec detection | scenario: http-crawl-non_statics
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:16:10
(1 day ago)
Brute-Force
Web App Attack
๐ฉ๐ช
Blexyel
2026-09-21 21:23:34
(1 day ago)
136.109.71.159 - - [21/Sep/2026:23:23:34 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
136.109.71.159 - - [21/Sep/2026:23:23:34 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
Sonoflet
2026-09-21 20:08:24
(1 day ago)
CrowdSec detection | scenario: http-bad-user-agent
Bad Web Bot
๐ฉ๐ช
macrob
2026-09-21 19:44:27
(1 day ago)
2026/09/21 19:44:26 [error] 1144019#1144019: *22587632 access forbidden by rule, client: 136.109.71. ...
show more
2026/09/21 19:44:26 [error] 1144019#1144019: *22587632 access forbidden by rule, client: 136.109.71.159, server: fn.binixo.es, request: "GET /.aws/config HTTP/2.0", host: "content.nuvello.org"
2026/09/21 19:44:26 [error] 1144022#1144022: *22587633 access forbidden by rule, client: 136.109.71.159, server: fn.binixo.es, request: "GET /.aws/credentials HTTP/2.0", host: "content.nuvello.org"
2026/09/21 19:44:26 [error] 1144022#1144022: *22587635 access forbidden by rule, client: 136.109.71.159, server: fn.binixo.es, request: "GET /.git/config HTTP/2.0", host: "content.nuvello.org"
...
show less
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-21 19:23:00
(1 day ago)
136.109.71.159 - - [21/Sep/2026:20:22:58 +0100] "GET /roundcube/ssl/localhost.key HTTP/2.0" 404 1064 ...
show more
136.109.71.159 - - [21/Sep/2026:20:22:58 +0100] "GET /roundcube/ssl/localhost.key HTTP/2.0" 404 1064 "https://webmail.simetria.org/ssl/localhost.key" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
show less
Bad Web Bot
๐ฉ๐ช
Starburst SysOp Team
2026-09-21 19:22:38
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-nue6-1)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 18:50:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.71.159 (159.71.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:50:46.686578 2026] [security2:error] [pid 7430:tid 7430] [client 136.109.71.159:53278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dc406.org"] [uri "/.git/HEAD"] [unique_id "arF8hoiHhQ5daBVphvHpwgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 18:46:04
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ง
gigatech
2026-09-21 18:45:03
(1 day ago)
Webserver Probing
Web App Attack