๐ฉ๐ช
NetShield-DE
2026-09-27 04:07:15
(43 minutes ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-27T ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-27T06:07:01+0200. Last: 2026-09-27T06:07:01+0200.
Samples:
- 2026-09-27 00:31:31,637 fail2ban.actions [858]: NOTICE [abuseipdb] Ban 136.70.199.3
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-27 03:37:50
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ฎ
sibahota
2026-09-27 02:33:59
(2 hours ago)
136.70.199.3 - - [27/Sep/2026:02:33:57 +0000] www.stockworld.co "GET /docker-compose.yml HTTP/1.1" 4 ...
show more
136.70.199.3 - - [27/Sep/2026:02:33:57 +0000] www.stockworld.co "GET /docker-compose.yml HTTP/1.1" 403 37 0.000 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" - - - "http://www.stockworld.co"
136.70.199.3 - - [27/Sep/2026:02:33:55 +0000] www.stockworld.co "GET /ubpz1j64x6ldb6ntovep HTTP/1.1" 403 37 0.000 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" - - - "http://www.stockworld.co"
...
show less
Bad Web Bot
๐บ๐ธ
gamabe
2026-09-27 02:33:10
(2 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐ฌ๐ง
Marten Mark
2026-09-27 00:02:10
(4 hours ago)
136.70.199.3 - - [27/Sep/2026:00:02:05 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Moz ...
show more
136.70.199.3 - - [27/Sep/2026:00:02:05 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
136.70.199.3 - - [27/Sep/2026:00:02:06 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.70.199.3 - - [27/Sep/2026:00:02:06 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.70.199.3 - - [27/Sep/2026:00:02:08 +0000] "GET /z9x8c7v6b5-debug-trigger-www.cfi.co HTTP/2.0" 404 22988 "https://www.cfi.co/z9x8c7v6b5-debug-trigger-www.cfi.co" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
136.70.199.3 - - [27/Sep/2026:00:02:08 +0000] "GET /z9x8c7v6b5-debug-trigger-www.cfi.co HTTP/2.0" 404 22988 "https://www.cfi.co/z9x8c7v6b5-debug-trigger-www.cfi.co" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like G
...
show less
Port Scan
Web App Attack
๐ฉ๐ช
NetShield-DE
2026-09-26 23:07:15
(5 hours ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-27T ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-27T01:07:01+0200. Last: 2026-09-27T01:07:01+0200.
Samples:
- 2026-09-27 00:31:31,637 fail2ban.actions [858]: NOTICE [abuseipdb] Ban 136.70.199.3
show less
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-09-26 22:16:10
(6 hours ago)
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/p9g161ne4qmtm9o1azya"
26/Sep/2026:22:16:09 +0000;136.70.19 ...
show more
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/p9g161ne4qmtm9o1azya"
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/z9x8c7v6b5-debug-trigger-vendors.katielewis.co"
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/ovpn1aqbecymjayl9vaw"
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/dist/manifest.json"
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/lib/terminal-xhr.php"
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/.vite/manifest.json"
26/Sep/2026:22:16:09 +0000;136.70.199.3;"/dist/.vite/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-09-26 20:52:46
(7 hours ago)
test.buscaempresas.co 136.70.199.3 - - [26/Sep/2026:15:52:45 -0500] "GET / HTTP/1.1" 444 0 "-" "Mozi ...
show more
test.buscaempresas.co 136.70.199.3 - - [26/Sep/2026:15:52:45 -0500] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" -
_ 136.70.199.3 - - [26/Sep/2026:15:52:45 -0500] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-" -
_ 136.70.199.3 - - [26/Sep/2026:15:52:45 -0500] "GET /static/../../../a/../../../../.env HTTP/1.1" 400 150 "-" "-" -
...
show less
Hacking
Web App Attack
๐ฉ๐ช
updown.io
2026-09-26 19:46:15
(9 hours ago)
{"level":"info","ts":1790451974.2789204,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790451974.2789204,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.70.199.3","remote_port":"44556","client_ip":"136.70.199.3","proto":"HTTP/2.0","method":"POST","host":"status.androutsos.co","uri":"/graphql","headers":{"Priority":["u=1, i"],"Referer":["https://status.androutsos.co"],"Sec-Fetch-Site":["same-origin"],"Sec-Ch-Ua-Platform":["\"Android\""],"Origin":["https://status.androutsos.co"],"Sec-Fetch-Mode":["cors"],"Content-Length":["86"],"Sec-Fetch-Dest":["empty"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"],"Accept-Encoding":["gzip, deflate, br, zstd"],"Content-Type":["application/json"],"Accept":["*/*"],"Sec-Ch-Ua-Mobile":["?1"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Google Chrome\";v=\"152\""]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
snappic
2026-09-26 18:24:37
(10 hours ago)
Scanning for config & DuckDuckGo Bot User Agent Spoofing [GET /config.json.js] [DuckAssistBot/1.1 (h ...
show more
Scanning for config & DuckDuckGo Bot User Agent Spoofing [GET /config.json.js] [DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
ruusvuu
2026-09-26 16:58:48
(11 hours ago)
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /config/env/a ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / US.
Targeted paths: /config/env/aws_credentials.env, /secrets.env, /secrets.yml, /asset-manifest.json, /credentials.json.
Sample log lines:
[rte] 136.70.199.3 [9/23/2026, 10:46:13 PM] "GET /.npmrc HTTP/1.1" 404 9889 "-"
[rte] 136.70.199.3 [9/23/2026, 10:46:13 PM] "GET /.npmrc HTTP/1.1" 404 9889 "-"
[rte] 136.70.199.3 [9/26/2026, 9:58:47 AM] "POST /api/graphql HTTP/1.1" 404 9889 "https://rte.whitneys.co"
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ฉ๐ช
spirttm
2026-09-26 16:00:36
(12 hours ago)
136.70.199.3 - - [26/Sep/2026:16:00:30 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/ ...
show more
136.70.199.3 - - [26/Sep/2026:16:00:30 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:30 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:30 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:31 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:31 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:35 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:35 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:35 +0000] "GET /..%2f.env HTTP/1.1" 400 157 "-" "-"
136.70.199.3 - - [26/Sep/2026:16:00:35 +0000] "GET /..%2f.env HTTP/1.1" 400 157 "-"
...
show less
Port Scan
Web App Attack
Anonymous
2026-09-26 14:59:10
(13 hours ago)
Multiple pen test attempts.
Web App Attack
๐บ๐ธ
snappic
2026-09-26 14:46:24
(14 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)]
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-26 13:34:44
(15 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking