🇬🇧
Marten Mark
2026-09-07 02:48:38
(58 minutes ago)
136.66.18.33 - - [07/Sep/2026:02:48:32 +0000] "GET /.docker/config.json HTTP/2.0" 404 23033 "https:/ ...
show more
136.66.18.33 - - [07/Sep/2026:02:48:32 +0000] "GET /.docker/config.json HTTP/2.0" 404 23033 "https://www.cfi.co/.docker/config.json" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
136.66.18.33 - - [07/Sep/2026:02:48:32 +0000] "GET /z9x8c7v6b5-debug-trigger-www.cfi.co HTTP/2.0" 404 23033 "https://www.cfi.co/z9x8c7v6b5-debug-trigger-www.cfi.co" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
136.66.18.33 - - [07/Sep/2026:02:48:32 +0000] "GET /.npmrc HTTP/2.0" 404 23033 "https://www.cfi.co/.npmrc" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
136.66.18.33 - - [07/Sep/2026:02:48:32 +0000] "GET /firebase-service-account.json HTTP/2.0" 404 23033 "https://www.cfi.co/firebase-service-account.json" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
136.66.18.33 - - [07/Sep/2026:02:48:33 +0000] "GET /.vite/manifest.json HTTP/2.0" 404 23033 "https://www.cfi.co/.vite/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Ge
...
show less
Port Scan
Web App Attack
Anonymous
2026-09-07 02:35:17
(1 hour ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇧🇪
cmbplf
2026-09-07 00:00:52
(3 hours ago)
2.305 requests from abuseipdb.com blacklisted IP (1yr6mos1w)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 17:00:27
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.18.33 (33.18.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.18.33 (33.18.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:00:18.856854 2026] [security2:error] [pid 23802:tid 23802] [client 136.66.18.33:59652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cuisine.gevieworld.com"] [uri "/img../.env"] [unique_id "ap2cImW3xbuIXZFDCvkAwgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 16:44:33
(11 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
mnsf
2026-09-06 16:05:23
(11 hours ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
🇪🇸
alferez
2026-09-06 14:48:01
(12 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:22:26
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.66.18.33 (33.18.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.18.33 (33.18.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:22:23.026859 2026] [security2:error] [pid 25794:tid 25794] [client 136.66.18.33:34712] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chuckbellmusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chuckbellmusic.com"] [uri "/z9x8c7v6b5-debug-trigger-chuckbellmusic.com"] [unique_id "ap13H1GormXpYno8C4cb7gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 14:17:18
(13 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 13:37:58
(14 hours ago)
136.66.18.33 - - [06/Sep/2026:09:37:58 -0400] "GET /%2eenv HTTP/1.1" 404 464 "-" "Mozilla/5.0 (compa ...
show more
136.66.18.33 - - [06/Sep/2026:09:37:58 -0400] "GET /%2eenv HTTP/1.1" 404 464 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
Web App Attack
SSH
🇫🇷
dynamix
2026-09-06 12:57:31
(14 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:44:37
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.18.33 (33.18.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.18.33 (33.18.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:44:33.173246 2026] [security2:error] [pid 6987:tid 6987] [client 136.66.18.33:41420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ctrussell.us"] [uri "/.env"] [unique_id "ap1gMRFBX0aHCB4Ha_QudwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-06 10:37:46
(17 hours ago)
(PERMBLOCK) 136.66.18.33 (US/United States/33.18.66.136.bc.googleusercontent.com) has had more than ...
show more
(PERMBLOCK) 136.66.18.33 (US/United States/33.18.66.136.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
🇮🇹
VHosting
2026-09-06 10:00:05
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇮🇹
ciccio diddo
2026-09-06 09:56:44
(17 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack