๐บ๐ธ
Mundo Bueno
2026-10-01 06:48:53
(1 week ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env [RATE ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env [RATE LIMITED - 1800s quarantine] | Pays: US | UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)
show less
Hacking
Web App Attack
๐ฉ๐ช
crypto i trust, hold i must
2026-10-01 06:21:31
(1 week ago)
Banned by fail2ban: nginx-botsearch
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:23:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.87.217 (217.87.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.87.217 (217.87.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:23:21.484820 2026] [security2:error] [pid 6424:tid 6424] [client 136.66.87.217:53398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepfer.org"] [uri "/.htpasswd"] [unique_id "ar3uSXLE0y9wZtNvSgHhaAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 02:01:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.87.217 (217.87.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.87.217 (217.87.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:01:05.559453 2026] [security2:error] [pid 17050:tid 17050] [client 136.66.87.217:43462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildimaginings.org"] [uri "/.htpasswd"] [unique_id "ar2-4YPCK9KjP4NCgmSl9QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-01 01:56:05
(1 week ago)
[Thu Oct 01 03:56:00.284579 2026] [security2:error] [pid 3870427:tid 3870439] [client 136.66.87.217: ...
show more
[Thu Oct 01 03:56:00.284579 2026] [security2:error] [pid 3870427:tid 3870439] [client 136.66.87.217:0] [client 136.66.87.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "eu.mmn.ca"] [uri "/"] [unique_id "ar29sO0jVNMjm4hbQBHCugAAAIo"]
[Thu Oct 01 03:56:04.182065 2026] [security2:error] [pid 3870399:tid 3870409] [client 136.66.87.217:0] [client 136.66.87.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evalua
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 01:23:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.87.217 (217.87.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.87.217 (217.87.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:23:55.362163 2026] [security2:error] [pid 16138:tid 16138] [client 136.66.87.217:47308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.texassportsmansassociation.org"] [uri "/static../.env"] [unique_id "ar22K6-7DzfdqywrBZAL0gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lavnet.net
2026-10-01 01:19:57
(1 week ago)
136.66.87.217 - - [01/Oct/2026:01:19:57 +0000] "GET /lzsggpmhj4pb8cpd674m HTTP/2.0" 404 1878 "-" "Mo ...
show more
136.66.87.217 - - [01/Oct/2026:01:19:57 +0000] "GET /lzsggpmhj4pb8cpd674m HTTP/2.0" 404 1878 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
136.66.87.217 - - [01/Oct/2026:01:19:57 +0000] "GET /model/info HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.66.87.217 - - [01/Oct/2026:01:19:57 +0000] "GET /ti5i7htcl0c2efiqeeop HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.66.87.217 - - [01/Oct/2026:01:19:57 +0000] "GET /z9x8c7v6b5-debug-trigger-www.a0a0.org HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
136.66.87.217 - - [01/Oct/2026:01:19:57 +0000] "POST /graphql HTTP/2.0" 404 1855 "https://www.a0a0.org" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.66.87.217 - - [01/Oct/2026:01:19:57 +0000] "POST /login HTTP/2.0" 404
...
show less
Brute-Force
๐ฌ๐ง
andypiper
2026-10-01 01:00:46
(1 week ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
crypto i trust, hold i must
2026-10-01 00:15:32
(1 week ago)
Web scanner path: /config/env/aws_credentials.env
Web App Attack
๐ฉ๐ช
macrob
2026-09-30 23:53:05
(1 week ago)
2026/09/30 23:53:04 [error] 1318202#1318202: *2884342 access forbidden by rule, client: 136.66.87.21 ...
show more
2026/09/30 23:53:04 [error] 1318202#1318202: *2884342 access forbidden by rule, client: 136.66.87.217, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "manage.wynspire.org"
2026/09/30 23:53:04 [error] 1318203#1318203: *2884350 access forbidden by rule, client: 136.66.87.217, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "manage.wynspire.org"
2026/09/30 23:53:04 [error] 1318207#1318207: *2884361 access forbidden by rule, client: 136.66.87.217, server: fn.binixo.es, request: "GET /.pypirc HTTP/2.0", host: "manage.wynspire.org"
...
show less
Web App Attack
๐ง๐ท
radardatelecom
2026-09-30 22:26:02
(1 week ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-30 22:16:40
(1 week ago)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 22:07:33
(1 week ago)
174 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-30 21:05:26
(1 week ago)
136.66.87.217 - - [30/Sep/2026:23:05:24 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT ...
show more
136.66.87.217 - - [30/Sep/2026:23:05:24 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.66.87.217 - - [30/Sep/2026:23:05:24 +0200] "GET /login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.66.87.217 - - [30/Sep/2026:23:05:24 +0200] "GET /signin HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.66.87.217 - - [30/Sep/2026:23:05:25 +0200] "GET /sign-in HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.66.87.217 - - [30/Sep/2026:23:05:25 +0200] "GET /auth/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.66.87.217 - - [30/
...
show less
Bad Web Bot
Web App Attack
๐ต๐น
rncbc
2026-09-30 20:12:49
(1 week ago)
[Wed Sep 30 21:12:42.555254 2026] [authz_core:error] [pid 841690:tid 841690] [client 136.66.87.217:4 ...
show more
[Wed Sep 30 21:12:42.555254 2026] [authz_core:error] [pid 841690:tid 841690] [client 136.66.87.217:47196] AH01630: client denied by server configuration: /srv/www/vhosts/rncbc/.htpasswd, referer: https://rncbc.org/.htpasswd
[Wed Sep 30 21:12:46.741748 2026] [authz_core:error] [pid 841698:tid 841698] [client 136.66.87.217:47274] AH01630: client denied by server configuration: /srv/www/cgi-bin/php-cgi.exe, referer: https://rncbc.org/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input
[Wed Sep 30 21:12:49.198069 2026] [authz_core:error] [pid 841693:tid 841693] [client 136.66.87.217:47232] AH01630: client denied by server configuration: /srv/www/cgi-bin/php-cgi, referer: https://rncbc.org/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input
...
show less
Brute-Force
Bad Web Bot
Web App Attack
SSH