🇧🇷
Halux
2026-09-06 19:14:12
(1 hour ago)
136.116.77.133 Probing protected path or service
Web App Attack
🇺🇸
mnsf
2026-09-06 18:05:05
(3 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
Anonymous
2026-09-06 15:39:06
(5 hours ago)
[Sun Sep 06 17:38:59.847026 2026] [access_compat:error] [pid 4101567:tid 4101567] [client 136.116.77 ...
show more
[Sun Sep 06 17:38:59.847026 2026] [access_compat:error] [pid 4101567:tid 4101567] [client 136.116.77.133:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/rclone.conf
[Sun Sep 06 17:39:04.205880 2026] [access_compat:error] [pid 4101567:tid 4101567] [client 136.116.77.133:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.npmrc
[Sun Sep 06 17:39:04.248934 2026] [access_compat:error] [pid 4099044:tid 4099044] [client 136.116.77.133:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.docker
[Sun Sep 06 17:39:04.900532 2026] [access_compat:error] [pid 4099051:tid 4099051] [client 136.116.77.133:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.s3cfg
[Sun Sep 06 17:39:04.903821 2026] [access_compat:error] [pid 4099044:tid 4099044] [client 136.116.77.133:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.
...
show less
Web Spam
Web App Attack
🇧🇪
Ivo Vynckier
2026-09-06 13:13:00
(7 hours ago)
136.116.77.133 - - [06/Sep/2026:07:16:08 +0200] "GET /z9x8c7v6b5-debug-trigger-spielberg-ocr.com HTT ...
show more
136.116.77.133 - - [06/Sep/2026:07:16:08 +0200] "GET /z9x8c7v6b5-debug-trigger-spielberg-ocr.com HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
136.116.77.133 - - [06/Sep/2026:07:16:08 +0200] "GET /ssl/server.key HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
136.116.77.133 - - [06/Sep/2026:07:16:08 +0200] "GET /rclone.conf HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
show less
Web App Attack
🇫🇷
dynamix
2026-09-06 12:21:52
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇮🇩
sockominfo
2026-09-06 12:00:53
(9 hours ago)
Active Response: IP 136.116.77.133 Blocked via Firewall Drop. Threat Score: 3.6/10 (LOW). Confidence ...
show more
Active Response: IP 136.116.77.133 Blocked via Firewall Drop. Threat Score: 3.6/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 36%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇮🇩
sockominfo
2026-09-06 11:00:53
(10 hours ago)
Active Response: IP 136.116.77.133 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence ...
show more
Active Response: IP 136.116.77.133 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇩🇪
grassau.com
2026-09-06 10:39:18
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.116.77.133 (US/United States/Iowa/C ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.116.77.133 (US/United States/Iowa/Council Bluffs/133.77.116.136.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
conseilgouz
2026-09-06 10:33:29
(10 hours ago)
doe-17 : Block hidden directories=>/_nuxt/../.env(/)
Hacking
🇮🇩
sockominfo
2026-09-06 10:00:10
(11 hours ago)
Active Response: IP 136.116.77.133 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Re ...
show more
Active Response: IP 136.116.77.133 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇩🇪
bazter.pro
2026-09-06 09:40:29
(11 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-06 08:49:50
(12 hours ago)
Blocked by ConnMonitor
Web App Attack
🇺🇸
Lee Daniel
2026-09-06 08:07:17
(12 hours ago)
136.116.77.133 - - [06/Sep/2026:04:07:16 -0400] "GET /.htpasswd HTTP/1.1" 403 6302 "-" "Mozilla/5.0 ...
show more
136.116.77.133 - - [06/Sep/2026:04:07:16 -0400] "GET /.htpasswd HTTP/1.1" 403 6302 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 08:06:12
(13 hours ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 08:03:53
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.116.77.133 (133.77.116.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.116.77.133 (133.77.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 04:03:46.282765 2026] [security2:error] [pid 4021303:tid 4021303] [client 136.116.77.133:40760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aupapierjaponais.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aupapierjaponais.com"] [uri "/rclone.conf"] [unique_id "ap0eYnX75EE-Jb50XEdC3wAAAGg"]
show less
Brute-Force
Bad Web Bot
Web App Attack