๐ณ๐ฑ
simon boshoff
2026-09-30 16:57:19
(8 minutes ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 15:28:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:28:14.685313 2026] [security2:error] [pid 9639:tid 9639] [client 136.70.110.195:35110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ccancun.co"] [uri "/.htpasswd"] [unique_id "ar0qjv5DE55UfOrbs3lVsQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
tpjg
2026-09-30 14:35:50
(2 hours ago)
Automated: 15 requests with error status in 120s window from 136.70.110.195.
Evidence: /Dockerfile:4 ...
show more
Automated: 15 requests with error status in 120s window from 136.70.110.195.
Evidence: /Dockerfile:404,/docker-compose.yaml:404,/docker-compose.yml:404,/api/graphql:404,/service_account.json:404,/firebase-adminsdk.json:404,/login:404,/firebase-service-account.json:404,/model/info:404,/graphql:404,/config/env/aws_credentials.env:404,/l1mcbmf1rvsh74j7h8sg:404,/zhx7h0ovozs9z7czvdkt:404,/z9x8c7v6b5-debug-trigger-ca1.wodo.co:404,/model/info:404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:39:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:39:20.956729 2026] [security2:error] [pid 2799:tid 2799] [client 136.70.110.195:37348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.waleed.co"] [uri "/.env.test"] [unique_id "ar0RCGfjBJ49Kni803iqrQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-30 12:51:11
(4 hours ago)
{"level":"info","ts":1790772667.6336253,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790772667.6336253,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.70.110.195","remote_port":"60508","client_ip":"136.70.110.195","proto":"HTTP/2.0","method":"GET","host":"status.vanleeuwen.co","uri":"/key.pem","headers":{"User-Agent":["Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"],"Accept":["*/*"],"Cookie":["REDACTED"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.vanleeuwen.co","ech":false}},"bytes_read":0,"user_id":"","duration":0.000118416,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790772667.6344628,"logger":"http.log.access.log1","ms
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:35:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:35:22.365865 2026] [security2:error] [pid 3459:tid 3459] [client 136.70.110.195:36884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mobileonlinecasinos.co"] [uri "/@fs/app/.env"] [unique_id "ar0CCmZUj5UCgouhWwPzewAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-30 12:30:39
(4 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
snappic
2026-09-30 11:52:23
(5 hours ago)
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (c ...
show more
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:10:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:10:14.402886 2026] [security2:error] [pid 27919:tid 27919] [client 136.70.110.195:59206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.qed-consulting.co"] [uri "/.env.staging"] [unique_id "arzuFjx2wnBVZPDzFdxPVAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
snappic
2026-09-30 10:51:05
(6 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhi ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:06:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:06:35.483532 2026] [security2:error] [pid 19869:tid 19869] [client 136.70.110.195:41728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tireking.co"] [uri "/.htpasswd"] [unique_id "arzfKxupQ11b25WVUMfMhAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Marten Mark
2026-09-30 10:01:20
(7 hours ago)
136.70.110.195 - - [30/Sep/2026:10:01:18 +0000] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 404 ...
show more
136.70.110.195 - - [30/Sep/2026:10:01:18 +0000] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 404 4065 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 09:44:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:43:52.574591 2026] [security2:error] [pid 16023:tid 16023] [client 136.70.110.195:47014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healthpointphysicians.co"] [uri "/.htpasswd"] [unique_id "arzZ2PiL-3227RM2RskydAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-09-30 09:42:01
(7 hours ago)
buscaempresas.co 136.70.110.195 - - [30/Sep/2026:04:41:54 -0500] "GET /__vite_rsc_findSourceMapURL?f ...
show more
buscaempresas.co 136.70.110.195 - - [30/Sep/2026:04:41:54 -0500] "GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc HTTP/2.0" 404 8196 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" MISS
buscaempresas.co 136.70.110.195 - - [30/Sep/2026:04:42:00 -0500] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/2.0" 403 6709 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" MISS
buscaempresas.co 136.70.110.195 - - [30/Sep/2026:04:42:00 -0500] "GET /api/system/fileView?file=/app/.env HTTP/2.0" 404 8196 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" MISS
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:20:55
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.110.195 (195.110.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:20:51.014193 2026] [security2:error] [pid 27169:tid 27169] [client 136.70.110.195:39274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cuul.co"] [uri "/media../.env"] [unique_id "arzUc6YP7dZU9VJznuaaIAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack