๐บ๐ธ
mnsf
2026-10-01 16:05:40
(9 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 15:28:06
(10 hours ago)
[ftpbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 136.6 ...
show more
[ftpbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 136.67.171.25 - - [01/Oct/2026:17:28:05 +0200] "GET /.env.js HTTP/1.1" 404 2101 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nightreaver
2026-10-01 15:21:03
(10 hours ago)
136.67.171.25 - - [01/Oct/2026:17:21:03 0200] "GET /0pkw18sl9jn3z6iapsz3 HTTP/1.1" 404 5721 "-" "Mo ...
show more
136.67.171.25 - - [01/Oct/2026:17:21:03 0200] "GET /0pkw18sl9jn3z6iapsz3 HTTP/1.1" 404 5721 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
136.67.171.25 - - [01/Oct/2026:17:21:03 0200] "GET /manifest.json HTTP/1.1" 404 5721 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
136.67.171.25 - - [01/Oct/2026:17:21:03 0200] "GET /asb3k55o1zg0dp5caixi HTTP/1.1" 404 5721 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; https://hunyuan.tencent.com/)"
136.67.171.25 - - [01/Oct/2026:17:21:03 0200] "GET /asset-manifest.json HTTP/1.1" 404 5721 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
136.67.171.25 - - [01/Oct/2026:17:21:03 0200] "GET /static/manifest.json HTTP/1.1" 404 5721 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0[...]
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-01 12:20:55
(13 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal, actuator, server_status, ignition_debug, aws_creds, ssh_keys, credential_file. Observed by 1 sensor(s); 479 hits.
show less
Hacking
Web App Attack
Anonymous
2026-10-01 12:15:14
(13 hours ago)
[ns1.skdns.gr] httpd-suspicious-path: iis-w3c
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-01 12:13:07
(13 hours ago)
Try to access /static../.env
Web App Attack
๐ฉ๐ช
zumbo.net
2026-10-01 11:57:26
(13 hours ago)
[Thu Oct 01 14:57:25.827715 2026] [proxy_fcgi:error] [pid 14101:tid 14126] [client 136.67.171.25:0] ...
show more
[Thu Oct 01 14:57:25.827715 2026] [proxy_fcgi:error] [pid 14101:tid 14126] [client 136.67.171.25:0] AH01071: Got error 'Primary script unknown', referer: https://www.surafikihkurulu.com/info.php
[Thu Oct 01 14:57:25.837518 2026] [proxy_fcgi:error] [pid 14101:tid 14133] [client 136.67.171.25:0] AH01071: Got error 'Primary script unknown', referer: https://www.surafikihkurulu.com/phpinfo.php
[Thu Oct 01 14:57:25.880230 2026] [proxy_fcgi:error] [pid 14101:tid 14116] [client 136.67.171.25:0] AH01071: Got error 'Primary script unknown', referer: https://www.surafikihkurulu.com/pi.php
[Thu Oct 01 14:57:26.047865 2026] [proxy_fcgi:error] [pid 14101:tid 14136] [client 136.67.171.25:0] AH01071: Got error 'Primary script unknown', referer: https://www.surafikihkurulu.com/test.php
[Thu Oct 01 14:57:26.075676 2026] [proxy_fcgi:error] [pid 14101:tid 14113] [client 136.67.171.25:0] AH01071: Got error 'Primary script unknown', referer: https://www.surafikihkurulu.com/i.php
...
show less
Brute-Force
Web App Attack
Anonymous
2026-10-01 11:50:07
(14 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
jormaster3k
2026-10-01 11:39:25
(14 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-01 10:58:25
(14 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.67.171.25 (US/United States/25.171.67.136.b ...
show more
(mod_security) mod_security (id:949110) triggered by 136.67.171.25 (US/United States/25.171.67.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-10-01 10:54:20
(14 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
Penny Packer
2026-10-01 10:40:15
(15 hours ago)
Fail2Ban apache-404
Web App Attack
๐ฉ๐ช
FD-IX
2026-10-01 10:23:34
(15 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 10:18:16
(15 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.67.171.25 - - [01/Oct/2026:12:17:56 +0200] "GET /static../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:02:01
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.67.171.25 (25.171.67.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.67.171.25 (25.171.67.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:01:54.433217 2026] [security2:error] [pid 21680:tid 21680] [client 136.67.171.25:33974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supportourlibrary.org"] [uri "/.htpasswd"] [unique_id "ar4vknj8vktQnwA4Wq_CSgAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack