This IP address has been reported a total of
52
times from
46 distinct
sources.
136.116.201.29 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Way too many 4xx errors in too short a time - Repeat offender 136.116.201.29 banned at least 2 times ...
show moreWay too many 4xx errors in too short a time - Repeat offender 136.116.201.29 banned at least 2 times in the last 7 days
show less
2026-09-24 07:24:48,295 fail2ban.actions [806406]: NOTICE [nginx-404] Ban 136.116.201.29
202 ...
show more2026-09-24 07:24:48,295 fail2ban.actions [806406]: NOTICE [nginx-404] Ban 136.116.201.29
2026-09-24 14:03:58,514 fail2ban.actions [806406]: NOTICE [nginx-404] Ban 136.116.201.29
...
show less
Hacking
Anonymous
LogGuard auto-report | score=150 | flags=flood | reasons=[+35] burst_10s_hard: 219 req in 10s (thres ...
show moreLogGuard auto-report | score=150 | flags=flood | reasons=[+35] burst_10s_hard: 219 req in 10s (threshold 100); [+20] burst_60s_suspicious: 219 req in 60s (threshold 200); [+20] burst_60s_suspicious: 219 req in 60s (threshold 200); [+25] error_ratio_severe: 82% error rate in 60s (179/219); [+25] path_diversity_severe: 191 unique paths in 60s (threshold 50)
show less
[ThuSep2410:35:13.9286612026][security2:error][pid3418779:tid3418869][client136.116.201.29:0]ModSecu ...
show more[ThuSep2410:35:13.9286612026][security2:error][pid3418779:tid3418869][client136.116.201.29:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"proc/self/\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:proc/self/foundwithinARGS:0:{\\\\x22then\\\\x22:\\\\x22\$1:__proto__:then\\\\x22\,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22\,\\\\x22reason\\\\x22:-1\,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22\$b1337/\\\\x22}\\\\x22\,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require\(\'child_process\'\).execsync\(\'env2\>/dev/null\|\|cat/proc/self/environ2\>/dev/null\'\)\;\\\\x22\,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22\$1:constructor:constructor\\\\x22}}}\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"aaaa6877.org\"][uri\"/\"][unique_id\"arTgwQaZ5NNWdluNIGz8BAAAAMQ\"]
show less
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show moreThis address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /config/secrets.yml | 2026-09-24 03:13 UTC
show less