Anonymous
2026-10-03 21:31:12
(1 minute ago)
2026/10/03 21:31:09 [error] 3693531#3693531: *14239 [client 136.116.9.218] ModSecurity: Access denie ...
show more
2026/10/03 21:31:09 [error] 3693531#3693531: *14239 [client 136.116.9.218] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.30.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "smscoregh.com"] [uri "/"] [unique_id "179106306918.156288"] [ref ""], client: 136.116.9.218, server: smscoregh.com, request: "POST / HTTP/2.0", host: "smscoregh.com"
2026/10/03 21:31:10 [error] 3693531#3693531: *14239 [client 136.116.9.218] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs-4.11.
...
show less
Brute-Force
๐ฉ๐ช
TheDjRider
2026-10-03 18:48:10
(2 hours ago)
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-crawl-non_stati ...
show more
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-crawl-non_statics. Automatic ban triggered. Detection time (UTC): 2026-10-03T18:47:58.438812782Z. Context: http_status=200
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
creechy
2026-10-03 11:10:29
(10 hours ago)
136.116.9.218 - - [03/Oct/2026:04:10:21 -0700] "GET /.dockerenv HTTP/1.1" 404 762 "-" "Mozilla/5.0 A ...
show more
136.116.9.218 - - [03/Oct/2026:04:10:21 -0700] "GET /.dockerenv HTTP/1.1" 404 762 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Hacking
Bad Web Bot
Anonymous
2026-10-03 10:52:46
(10 hours ago)
GET wp-json | UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot) | Time: 2026-10-03 10:5 ...
show more
GET wp-json | UA: Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot) | Time: 2026-10-03 10:52:46 UTC
show less
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-03 10:10:24
(11 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-10-03T10:10:07.12401821Z. Context: http_status=403, http_status=404
show less
Web App Attack
๐ฉ๐ช
updown.io
2026-10-03 09:01:31
(12 hours ago)
{"level":"info","ts":1791018090.0874197,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791018090.0874197,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.116.9.218","remote_port":"56548","client_ip":"136.116.9.218","proto":"HTTP/2.0","method":"GET","host":"status.pittohio.com","uri":"/static/manifest.json","headers":{"X-Nextjs-Data":["1"],"Sec-Ch-Ua-Mobile":["?0"],"Sec-Ch-Ua-Platform":["\"Windows\""],"Sec-Fetch-Mode":["navigate"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Microsoft Edge\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Fetch-User":["?1"],"Priority":["u=0, i"],"Sec-Fetch-Dest":["document"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Accept-Language":["en-US,en;q=0.9"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"],"Sec-Fetch
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 07:59:41
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.116.9.218 (218.9.116.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.116.9.218 (218.9.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:59:36.082689 2026] [security2:error] [pid 2189:tid 2189] [client 136.116.9.218:36784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.colemangray.com|F|2"] [data ".colemangray.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.colemangray.com"] [uri "/z9x8c7v6b5-debug-trigger-www.colemangray.com"] [unique_id "asC16B9703_ggi4m665ZBAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dimitar Penkov
2026-10-03 04:33:14
(16 hours ago)
DDOS flood attempts
Brute-Force
Exploited Host
Anonymous
2026-10-03 04:12:59
(17 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:16:50
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.116.9.218 (218.9.116.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.116.9.218 (218.9.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:16:44.907808 2026] [security2:error] [pid 11480:tid 11480] [client 136.116.9.218:55274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.milliondollarbelt.com"] [uri "/.env.js"] [unique_id "asBznIqvMJ4UVExEaRSIwQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 19:33:57
(1 day ago)
136.116.9.218 - - [02/Oct/2026:14:32:30 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
136.116.9.218 - - [02/Oct/2026:14:32:30 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 136.116.9.218
136.116.9.218 - - [02/Oct/2026:14:32:31 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 136.116.9.218
136.116.9.218 - - [02/Oct/2026:14:32:31 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 136.116.9.218
136.116.9.218 - - [02/Oct/2026:14:32:31 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 136.116.9.218
136.116.9.218 - - [02/Oct/2026:14:32:31 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 136.116.9.218
136.116.9.218 - - [02/Oct/2026:14:32:31 -0500] "GET /.env.test HTTP/1.1" 403 199 "-"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-10-02 19:30:22
(1 day ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ฎ๐ช
RoboSOC
2026-10-02 16:24:45
(1 day ago)
PHP CGI Argument Injection Vulnerability, PTR: 218.9.116.136.bc.googleusercontent.com.
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 14:55:29
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.116.9.218 (218.9.116.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.116.9.218 (218.9.116.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:55:23.354401 2026] [security2:error] [pid 18000:tid 18000] [client 136.116.9.218:56718] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wsspy.com|F|2"] [data ".wsspy.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wsspy.com"] [uri "/z9x8c7v6b5-debug-trigger-www.wsspy.com"] [unique_id "ar_F26mIry-KfmwLWO4fJwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
creechy
2026-10-02 09:13:30
(1 day ago)
136.116.9.218 - - [02/Oct/2026:02:13:21 -0700] "GET /static//home/user/.env HTTP/1.1" 404 790 "-" "M ...
show more
136.116.9.218 - - [02/Oct/2026:02:13:21 -0700] "GET /static//home/user/.env HTTP/1.1" 404 790 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Hacking
Bad Web Bot