๐ง๐ช
cmbplf
2026-10-07 02:29:34
(2 days ago)
690 requests with url.path *.env
418 requests with url.path */@fs/*
109 requests with url.path */ ...
show more
690 requests with url.path *.env
418 requests with url.path */@fs/*
109 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-07 00:44:21
(2 days ago)
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.70.132.49 - - [07/Oct/2026:02:44:12 +0200] "GET /.htpasswd HTTP/2.0" 301 284 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-06 18:46:48
(3 days ago)
{"level":"info","ts":1791312405.4381897,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791312405.4381897,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.70.132.49","remote_port":"53322","client_ip":"136.70.132.49","proto":"HTTP/2.0","method":"GET","host":"status.flow.bio","uri":"/dist/manifest.json","headers":{"Sec-Fetch-Dest":["document"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Priority":["u=0, i"],"Sec-Fetch-Mode":["navigate"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Brave\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Ch-Ua-Platform":["\"Linux\""],"Sec-Fetch-User":["?1"],"Upgrade-Insecure-Requests":["1"],"Accept-Language":["en-US,en;q=0.9"],"X-Nextjs-Data":["1"],"Sec-Ch-Ua-Mobile":["?0"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Accept":["text/h
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-10-06 17:44:04
(3 days ago)
136.70.132.49 - - [06/Oct/2026:17:44:03 +0000] "GET /files../.env HTTP/2.0" 302 318 "-" "CCBot/2.0 ( ...
show more
136.70.132.49 - - [06/Oct/2026:17:44:03 +0000] "GET /files../.env HTTP/2.0" 302 318 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:08:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:08:08.174589 2026] [security2:error] [pid 22717:tid 22717] [client 136.70.132.49:34500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.alknetso.name"] [uri "/js../.env"] [unique_id "asTIiD-rgeHuAhE8HatcXwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:40:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:40:00.772272 2026] [security2:error] [pid 7053:tid 7053] [client 136.70.132.49:42040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.james.ahlstrom.name"] [uri "/files../.env"] [unique_id "asSz4DcH5ghIhxsfpaXf1AAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
amyriad
2026-10-06 08:25:04
(3 days ago)
136.70.132.49 - - [06/Oct/2026:08:25:03 +0000] "GET /.ssh/id_rsa HTTP/1.1" 404 459 "-" "Mozilla/5.0 ...
show more
136.70.132.49 - - [06/Oct/2026:08:25:03 +0000] "GET /.ssh/id_rsa HTTP/1.1" 404 459 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
136.70.132.49 - - [06/Oct/2026:08:25:03 +0000] "GET /.ssh/id_ed25519 HTTP/1.1" 404 459 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
136.70.132.49 - - [06/Oct/2026:08:25:03 +0000] "GET /.ssh/config HTTP/1.1" 404 459 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
DDoS Attack
Hacking
Brute-Force
๐ฌ๐ง
oja
2026-10-06 08:12:35
(3 days ago)
Aggressive web scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:50:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:50:40.568774 2026] [security2:error] [pid 14641:tid 14641] [client 136.70.132.49:41202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wies.name"] [uri "/.htpasswd"] [unique_id "asSoUIgzEz06m8uCaQ0S4wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:27:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:27:11.860076 2026] [security2:error] [pid 13581:tid 13581] [client 136.70.132.49:48762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ribas.name"] [uri "/.htpasswd"] [unique_id "asSiz8j-94kD-6b4325nBwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
mindrider
2026-10-06 07:16:11
(3 days ago)
136.70.132.49 - - [06/Oct/2026:09:16:08 +0200] "GET /public/plugins/text/../../../../../../../../pro ...
show more
136.70.132.49 - - [06/Oct/2026:09:16:08 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 500 170 "-" "-" "-"
136.70.132.49 - - [06/Oct/2026:09:16:08 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 2968 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-"
...
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-10-06 07:05:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:03:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.132.49 (49.132.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:03:14.023541 2026] [security2:error] [pid 6673:tid 6683] [client 136.70.132.49:59510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailme.name"] [uri "/build../.env"] [unique_id "asSdMlCh4fvsT9-iZAdIRAAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
onlyops.app
2026-10-06 07:00:09
(3 days ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
๐ฌ๐ง
consul.to
2026-10-06 06:58:21
(3 days ago)
Web attack/malicious scanning detected
Web App Attack