๐จ๐ฑ
SinaiCL
2026-07-22 03:55:13
(2 days ago)
WAF Multiple Hits
Bad Web Bot
Web App Attack
๐ง๐ช
Ivo Vynckier
2026-07-21 10:44:00
(2 days ago)
136.66.198.137 - - [21/Jul/2026:02:14:12 +0200] "GET /host.key HTTP/2.0" 404 2310 "-" "Mozilla/5.0 A ...
show more
136.66.198.137 - - [21/Jul/2026:02:14:12 +0200] "GET /host.key HTTP/2.0" 404 2310 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
136.66.198.137 - - [21/Jul/2026:02:14:12 +0200] "GET /.bashrc HTTP/2.0" 404 2310 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
136.66.198.137 - - [21/Jul/2026:02:14:12 +0200] "GET /manifest.json HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 YaBrowser/26.6.0.0 Safari/537.36"
136.66.198.137 - - [21/Jul/2026:02:14:12 +0200] "GET /webpack-stats.json HTTP/2.0" 404 2310 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
show less
Web App Attack
๐ซ๐ท
IRISIO
2026-07-21 10:43:55
(2 days ago)
scans/SQL injection/spam posts : 757 queries
Web App Attack
SQL Injection
๐ฎ๐ณ
evicky2002
2026-07-21 06:00:00
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-07-21 04:31:43
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฆ๐น
penguin-solutions.at
2026-07-21 02:30:39
(3 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐บ๐ธ
MaxSmartCode
2026-07-21 02:28:59
(3 days ago)
Credential brute-force attacks on webpage.
Brute-Force
SSH
Anonymous
2026-07-21 02:26:04
(3 days ago)
Multiple pen test attempts.
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-21 02:18:34
(3 days ago)
136.66.198.137 - - [21/Jul/2026:05:18:33 +0300] "GET /.env HTTP/1.1" 404 4601 "-" "Mozilla/5.0 Apple ...
show more
136.66.198.137 - - [21/Jul/2026:05:18:33 +0300] "GET /.env HTTP/1.1" 404 4601 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
...
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-21 01:48:57
(3 days ago)
cloudlinux2 fail2ban: 2026-07-21 03:45:14,984 fail2ban.filter [1927]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-21 03:45:14,984 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 45.132.227.170 - 2026-07-21 03:45:14cloudlinux2 fail2ban: 2026-07-21 03:46:44,281 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 136.66.198.137 - 2026-07-21 03:46:44cloudlinux2 fail2ban: 2026-07-21 03:46:44,085 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 136.66.198.137 - 2026-07-21 03:46:44cloudlinux2 fail2ban: 2026-07-21 03:46:44,484 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 136.66.198.137 - 2026-07-21 03:46:44cloudlinux2 fail2ban: 2026-07-21 03:46:44,429 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 136.66.198.137 - 2026-07-21 03:46:44cloudlinux2 fail2ban: 2026-07-21 03:46:44,448 fail2ban.actions [1927]: NOTICE [plesk-modsecurity] Ban 136.66.198.137cloudlinux2 fail2ban: 2026-07-21 03:46:44,073 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 136.66.198.137 - 2026-07-21 03:46:44cloudlinux2 fa
show less
Web App Attack
๐ฉ๐ช
macrob
2026-07-21 01:44:10
(3 days ago)
2026/07/21 01:44:09 [error] 2087332#2087332: *394479182 access forbidden by rule, client: 136.66.198 ...
show more
2026/07/21 01:44:09 [error] 2087332#2087332: *394479182 access forbidden by rule, client: 136.66.198.137, server: binixo.mx, request: "GET /.aws/config HTTP/2.0", host: "binixo.mx"
2026/07/21 01:44:09 [error] 2087332#2087332: *394479182 access forbidden by rule, client: 136.66.198.137, server: binixo.mx, request: "GET /.github/workflows/deploy.yml HTTP/2.0", host: "binixo.mx"
2026/07/21 01:44:09 [error] 2087332#2087332: *394479182 access forbidden by rule, client: 136.66.198.137, server: binixo.mx, request: "GET /.git/config HTTP/2.0", host: "binixo.mx"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 01:41:32
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 136.66.198.137 (137.198.66.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.66.198.137 (137.198.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 21:41:27.092615 2026] [security2:error] [pid 15239:tid 15316] [client 136.66.198.137:53940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clearwaterpumpservices.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clearwaterpumpservices.com"] [uri "/rclone.conf"] [unique_id "al7OR_NplCE4ZCLCiQwZPQAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-07-21 01:27:14
(3 days ago)
[21/Jul/2026:03:27:13.774168 +0200] al7K8YTuDmNHMBbi1sPiqgAAAAU 136.66.198.137 56716 127.0.0.1 7081
...
show more
[21/Jul/2026:03:27:13.774168 +0200] al7K8YTuDmNHMBbi1sPiqgAAAAU 136.66.198.137 56716 127.0.0.1 7081
[21/Jul/2026:03:27:13.795784 +0200] al7K8bHW5FxOFB0dgViS-AAAAAQ 136.66.198.137 56742 127.0.0.1 7081
[21/Jul/2026:03:27:13.826504 +0200] al7K8VV8uNwb0PmxWwBOTgAAAAM 136.66.198.137 56778 127.0.0.1 7081
...
show less
Hacking
๐บ๐ธ
xpto
2026-07-21 01:16:42
(3 days ago)
Blocked for probing for web application vulnerabilities
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-07-21 01:12:57
(3 days ago)
136.66.198.137 - - [21/Jul/2026:02:12:57 +0100] "GET /z9x8c7v6b5-debug-trigger-www.trailrides-wales. ...
show more
136.66.198.137 - - [21/Jul/2026:02:12:57 +0100] "GET /z9x8c7v6b5-debug-trigger-www.trailrides-wales.com HTTP/1.1" 403 6433 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
...
show less
Bad Web Bot