Anonymous
2026-09-30 18:44:02
(1 hour ago)
Web Attack Next.js Authorization Bypass Vulnerability
Web App Attack
๐บ๐ธ
WellSpring
2026-09-30 17:02:47
(2 hours ago)
env leak on strangertable.org/api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env โ WellSpr.ing ...
show more
env leak on strangertable.org/api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env โ WellSpr.ing/NetSentinel civic-AI security layer
show less
Web App Attack
๐ณ๐ฑ
mieg
2026-09-30 16:41:56
(3 hours ago)
Web vulnerability probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:43:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:43:50.006416 2026] [security2:error] [pid 18739:tid 18739] [client 136.64.55.91:36318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.valueproducersalliance.org"] [uri "/@fs/app/.env"] [unique_id "ar0uNkqgeo8cpjEN4w8IlAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:40:29
(5 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:29:22
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:29:19.080741 2026] [security2:error] [pid 29403:tid 29403] [client 136.64.55.91:54226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.texassportsmansassociation.org"] [uri "/static//home/user/.env"] [unique_id "ar0cv_sWF_f0ybFEZqw-FQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:13:56
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-30 13:40:07
(6 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-30 12:58:47
(7 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-09-30 12:39:43
(7 hours ago)
Fail2Ban apache-noscript
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 12:26:06
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:26:03.164672 2026] [security2:error] [pid 15553:tid 15553] [client 136.64.55.91:53480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.vekk.org"] [uri "/dist../.env"] [unique_id "arz_25rbqmAm3P9DWLtLigAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-30 12:07:54
(7 hours ago)
136.64.55.91 - - [30/Sep/2026:22:07:54 +1000] "GET /model/info HTTP/2.0" 404 993 "-" "CCBot/2.0 (htt ...
show more
136.64.55.91 - - [30/Sep/2026:22:07:54 +1000] "GET /model/info HTTP/2.0" 404 993 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
136.64.55.91 - - [30/Sep/2026:22:07:54 +1000] "GET /70bommnm6abuk53u425s HTTP/2.0" 404 993 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
136.64.55.91 - - [30/Sep/2026:22:07:54 +1000] "GET /z9x8c7v6b5-debug-trigger-uploads.aranguren.org HTTP/2.0" 404 993 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.64.55.91 - - [30/Sep/2026:22:07:54 +1000] "POST / HTTP/2.0" 406 - "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
136.64.55.91 - - [30/Sep/2026:22:07:54 +1000] "GET /ap9ivd6dz3ypmd8b5go0 HTTP/2.0" 404 993 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
136.64.55.91 - - [30/Sep/2026:22:07:54 +1000] "POST /graphql HTTP/2.0" 404 1136 "https://uploads.aranguren.org" "M
...
show less
Bad Web Bot
๐ฉ๐ช
Marc
2026-09-30 11:41:46
(8 hours ago)
136.64.55.91 - - [30/Sep/2026:13:41:46 +0200] "GET /secure HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Windo ...
show more
136.64.55.91 - - [30/Sep/2026:13:41:46 +0200] "GET /secure HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 136.64.55.91 - - [30/Sep/2026:13:41:46 +0200] "GET /auth HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 136.64.55.91 - - [30/Sep/2026:13:41:46 +0200] "GET /ckkzwh4t8sdjsq8iwvw2 HTTP/2.0" 404 269 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 11:28:34
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.64.55.91 (91.55.64.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:28:29.796092 2026] [security2:error] [pid 12557:tid 12557] [client 136.64.55.91:60562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.templegardens.org"] [uri "/assets../.env"] [unique_id "arzyXTgYbNiRXNXitkHmWQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 10:59:19
(9 hours ago)
136.64.55.91 - - [30/Sep/2026:12:59:19 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Andr ...
show more
136.64.55.91 - - [30/Sep/2026:12:59:19 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.64.55.91 - - [30/Sep/2026:12:59:19 +0200] "POST / HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
136.64.55.91 - - [30/Sep/2026:12:59:19 +0200] "GET /j49fwztxpcpkydgdg8m6 HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
136.64.55.91 - - [30/Sep/2026:12:59:19 +0200] "GET /portal HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.64.55.91 - - [30/Sep/2026:12:59:19 +0200] "GET /secure HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/1
...
show less
Bad Web Bot
Web App Attack