๐ซ๐ท
UnixPrime
2026-09-23 02:54:08
(4 hours ago)
136.67.148.161 - - [23/Sep/2026:04:54:06 +0200] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compa ...
show more
136.67.148.161 - - [23/Sep/2026:04:54:06 +0200] "GET /.env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
136.67.148.161 - - [23/Sep/2026:04:54:07 +0200] "GET /.env.production HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 23:57:14
(7 hours ago)
136.67.148.161 - - [22/Sep/2026:23:56:12 +0000] "GET /.dockerenv HTTP/2.0" 403 196 "-" "Mozilla/5.0 ...
show more
136.67.148.161 - - [22/Sep/2026:23:56:12 +0000] "GET /.dockerenv HTTP/2.0" 403 196 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-"
136.67.148.161 - - [22/Sep/2026:23:56:12 +0000] "GET /.env?raw HTTP/2.0" 403 196 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-"
136.67.148.161 - - [22/Sep/2026:23:56:12 +0000] "GET /.env?import&raw HTTP/2.0" 403 196 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-"
136.67.148.161 - - [22/Sep/2026:23:56:12 +0000] "GET /.env.local?raw HTTP/2.0" 403 196 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-"
136.67.148.161 - - [22/Sep/2026:23:56:12 +0000] "GET /.env?import&url&inline HTTP/2.0" 403 196 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-"
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 22:00:45
(9 hours ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐บ๐ธ
Sonoflet
2026-09-22 21:19:52
(10 hours ago)
CrowdSec detection | scenario: http-crawl-non_statics
Bad Web Bot
๐ฉ๐ช
Marc
2026-09-22 21:05:57
(10 hours ago)
136.67.148.161 - - [22/Sep/2026:23:05:57 +0200] "GET /account/login HTTP/2.0" 404 291 "-" "Mozilla/5 ...
show more
136.67.148.161 - - [22/Sep/2026:23:05:57 +0200] "GET /account/login HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 136.67.148.161 - - [22/Sep/2026:23:05:57 +0200] "GET /l403p9pjfdft74n7h43y HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 136.67.148.161 - - [22/Sep/2026:23:05:57 +0200] "GET /sign-in HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
show less
Brute-Force
๐บ๐ธ
Sonoflet
2026-09-22 20:48:30
(10 hours ago)
CrowdSec detection | scenario: http-path-traversal-probing
Web App Attack
Exploited Host
๐บ๐ธ
Sonoflet
2026-09-22 20:13:16
(11 hours ago)
CrowdSec detection | scenario: thinkphp-cve-2018-20062
Web App Attack
Exploited Host
๐บ๐ธ
Sonoflet
2026-09-22 19:50:56
(11 hours ago)
CrowdSec detection | scenario: http-bad-user-agent
Bad Web Bot
๐ซ๐ท
Octopuce
2026-09-22 18:32:38
(13 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /static../.env /media../.env /files../.env ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /static../.env /media../.env /files../.env /static//.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:05:34
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.67.148.161 (161.148.67.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.67.148.161 (161.148.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:05:30.501423 2026] [security2:error] [pid 28808:tid 28808] [client 136.67.148.161:37606] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.myclub.oxfordgliding.com|F|2"] [data ".myclub.oxfordgliding.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.myclub.oxfordgliding.com"] [uri "/z9x8c7v6b5-debug-trigger-www.myclub.oxfordgliding.com"] [unique_id "arLDalmE9AL4X6bBx9d5DwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Sonoflet
2026-09-22 17:22:40
(14 hours ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐ช๐ธ
robotstxt
2026-09-22 17:16:17
(14 hours ago)
136.67.148.161 - - [22/Sep/2026:17:15:17 +0000] "GET /z9x8c7v6b5-debug-trigger-www.labodadelany.cat ...
show more
136.67.148.161 - - [22/Sep/2026:17:15:17 +0000] "GET /z9x8c7v6b5-debug-trigger-www.labodadelany.cat HTTP/2.0" 403 12675 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="136.67.148.161"
136.67.148.161 - - [22/Sep/2026:17:15:17 +0000] "GET /kl0bya1zwytdyac2dwic/ HTTP/2.0" 403 12675 "https://www.labodadelany.cat/kl0bya1zwytdyac2dwic" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "-" edge="136.67.148.161"
136.67.148.161 - - [22/Sep/2026:17:15:17 +0000] "POST / HTTP/2.0" 403 25748 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-" edge="136.67.148.161"
136.67.148.161 - - [22/Sep/2026:17:15:18 +0000] "GET /mwkfpgk8qjuoxxyajq8n/ HTTP/2.0" 403 12675 "https://www.labodadelany.cat/mwkfpgk8qjuoxxyajq8n" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "-" edge="136.67.148.161"
136.
...
show less
Web App Attack
๐ซ๐ท
COMAITE
2026-09-22 16:30:19
(15 hours ago)
Common web attack from 136.67.148.161.
Web App Attack
๐ฉ๐ช
maxpower
2026-09-22 16:18:54
(15 hours ago)
(PERMBLOCK) 136.67.148.161 (US/United States/161.148.67.136.bc.googleusercontent.com) has had more t ...
show more
(PERMBLOCK) 136.67.148.161 (US/United States/161.148.67.136.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ธ๐ช
vaia.cloud
2026-09-22 14:15:03
(17 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack