🇬🇧
Marten Mark
2026-09-12 15:00:47
(6 hours ago)
136.67.109.89 - - [12/Sep/2026:15:00:43 +0000] "GET /rclone.conf HTTP/2.0" 404 23033 "https://www.cf ...
show more
136.67.109.89 - - [12/Sep/2026:15:00:43 +0000] "GET /rclone.conf HTTP/2.0" 404 23033 "https://www.cfi.co/rclone.conf" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
136.67.109.89 - - [12/Sep/2026:15:00:43 +0000] "GET /z9x8c7v6b5-debug-trigger-www.cfi.co HTTP/2.0" 404 23033 "https://www.cfi.co/z9x8c7v6b5-debug-trigger-www.cfi.co" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.67.109.89 - - [12/Sep/2026:15:00:43 +0000] "GET /z9x8c7v6b5-debug-trigger-www.cfi.co HTTP/2.0" 404 23033 "https://www.cfi.co/z9x8c7v6b5-debug-trigger-www.cfi.co" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.67.109.89 - - [12/Sep/2026:15:00:44 +0000] "GET /build/manifest.json HTTP/2.0" 404 23033 "https://www.cfi.co/build/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.36"
136.67.109.89 - - [12/Sep/2026:15:00:44 +0000] "GET /build/manifest.json HTTP/2.0" 404 23033 "https://www.cfi.co
...
show less
Port Scan
Web App Attack
🇩🇪
macrob
2026-09-12 14:44:27
(7 hours ago)
2026/09/12 14:44:26 [error] 984476#984476: *4702696 access forbidden by rule, client: 136.67.109.89, ...
show more
2026/09/12 14:44:26 [error] 984476#984476: *4702696 access forbidden by rule, client: 136.67.109.89, server: binixo.co, request: "GET //.env HTTP/2.0", host: "www.binixo.co"
2026/09/12 14:44:26 [error] 984476#984476: *4702698 access forbidden by rule, client: 136.67.109.89, server: binixo.co, request: "GET /api/.env/public/.env HTTP/2.0", host: "www.binixo.co"
2026/09/12 14:44:26 [error] 984476#984476: *4702699 access forbidden by rule, client: 136.67.109.89, server: binixo.co, request: "GET /.//.env HTTP/2.0", host: "www.binixo.co"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 14:06:42
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 10:06:35.414290 2026] [security2:error] [pid 28326:tid 28326] [client 136.67.109.89:58662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fasllc.co"] [uri "/@fs/.env"] [unique_id "aqVca9ifnv02oj4fhCBVnwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-09-12 14:03:04
(7 hours ago)
(PERMBLOCK) 136.67.109.89 (US/United States/Oregon/The Dalles/89.109.67.136.bc.googleusercontent.com ...
show more
(PERMBLOCK) 136.67.109.89 (US/United States/Oregon/The Dalles/89.109.67.136.bc.googleusercontent.com/[redacted]) has had more than 2 temp blocks
show less
Hacking
🇿🇦
conure.sh
2026-09-12 05:43:05
(16 hours ago)
csagent: score 22.2: 404 noise floor x9, secrets grab x2; 1 domain(s) in 2s
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-11 22:15:23
(23 hours ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:51:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:51:20.869482 2026] [security2:error] [pid 12502:tid 12502] [client 136.67.109.89:46702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forwardfusion.co"] [uri "/@fs/../.env"] [unique_id "aqRNqJr9KZEGqX6zSbWTlwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
ELYAZ
2026-09-11 18:13:44
(1 day ago)
(y3) Failed access -byebye- from 136.67.109.89 (US/United States/89.109.67.136.bc.googleusercontent. ...
show more
(y3) Failed access -byebye- from 136.67.109.89 (US/United States/89.109.67.136.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇮🇹
VHosting
2026-09-11 17:35:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:12:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:12:17.225486 2026] [security2:error] [pid 10837:tid 10837] [client 136.67.109.89:46758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cookes.co"] [uri "/.git/config"] [unique_id "aqQ2cRC3GcK-KLFrZU4HPwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-09-11 17:01:43
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
IndigoRidge
2026-09-11 16:54:18
(1 day ago)
136.67.109.89 - - [11/Sep/2026:12:54:12 -0400] "GET /.git/config HTTP/1.1" 403 4905 "-" "Mozilla/5.0 ...
show more
136.67.109.89 - - [11/Sep/2026:12:54:12 -0400] "GET /.git/config HTTP/1.1" 403 4905 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
136.67.109.89 - - [11/Sep/2026:12:54:12 -0400] "GET /.aws/credentials HTTP/1.1" 404 81159 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
136.67.109.89 - - [11/Sep/2026:12:54:17 -0400] "GET /.//.env HTTP/1.1" 301 4747 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Web App Attack
🇬🇧
Marten Mark
2026-09-11 16:44:35
(1 day ago)
136.67.109.89 - - [11/Sep/2026:16:44:34 +0000] "GET /.aws/credentials HTTP/2.0" 404 23033 "-" "Mozil ...
show more
136.67.109.89 - - [11/Sep/2026:16:44:34 +0000] "GET /.aws/credentials HTTP/2.0" 404 23033 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Web App Attack
Bad Web Bot
🇲🇾
Rizzy
2026-09-11 16:42:52
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:41:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.109.89 (89.109.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:41:32.468324 2026] [security2:error] [pid 24507:tid 24507] [client 136.67.109.89:32916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ccancun.co"] [uri "/@fs/.env"] [unique_id "aqQvPDlbasf5gx_2X6ynZgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack