๐ฌ๐ง
WebNiraj
2026-08-18 19:14:00
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 136.66.198.115 (US/United States/115.198.66.136 ...
show more
(mod_security) mod_security (id:949110) triggered by 136.66.198.115 (US/United States/115.198.66.136.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐ซ๐ท
Catalin Negru
2026-08-18 18:51:57
(4 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ฎ๐น
VHosting
2026-08-18 18:20:06
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-18 18:07:25
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-18 00:11:59
(5 days ago)
Excessive multi-domain requests
Brute-Force
๐ฟ๐ฆ
conure.sh
2026-08-17 23:31:58
(5 days ago)
csagent: score 22.5: 404 noise floor x10, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-17 21:55:02
(5 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-17 19:00:04
(5 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
jormaster3k
2026-08-17 15:22:00
(5 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-17 13:32:29
(5 days ago)
[17/Aug/2026:16:32:29 +0300] -- 136.66.198.115 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET ...
show more
[17/Aug/2026:16:32:29 +0300] -- 136.66.198.115 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /manifest.json HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-08-17 10:54:58
(5 days ago)
Web scanning / probing for vulnerable paths | URL: /service-account.json | Evidence: primeiraclasse. ...
show more
Web scanning / probing for vulnerable paths | URL: /service-account.json | Evidence: primeiraclasse.pt 136.66.198.115 - - [17/Aug/2026:12:54:09 +0200] \"GET /service-account.json HTTP/2.0\" 404 22476 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email]\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 07:47:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 136.66.198.115 (115.198.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.198.115 (115.198.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 03:47:18.251182 2026] [security2:error] [pid 26241:tid 26241] [client 136.66.198.115:58030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.oceanrich.biz"] [uri "/.env"] [unique_id "aoK8hmv_pEUY45-5EyuYnAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-17 06:00:04
(5 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 03:44:10
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.66.198.115 (115.198.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.198.115 (115.198.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 23:44:06.521842 2026] [security2:error] [pid 22808:tid 22808] [client 136.66.198.115:60376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.roguetechink.com"] [uri "/.openclaw/.env"] [unique_id "aoKDhvSnNY5gMnErOUcosQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 01:57:17
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 136.66.198.115 (115.198.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.198.115 (115.198.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:57:09.937611 2026] [security2:error] [pid 7716:tid 7716] [client 136.66.198.115:50982] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sandersonpropertyimprovements.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sandersonpropertyimprovements.com"] [uri "/rclone.conf"] [unique_id "aoJqdYBls9kIlkhQCVOmVwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack