๐บ๐ธ
gamabe
2026-10-01 05:12:25
(18 hours ago)
Detected crowdsecurity/http-dos-swithcing-ua attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 04:38:47
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:38:42.520173 2026] [security2:error] [pid 27959:tid 27959] [client 136.70.209.133:51262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.h2ofall.co"] [uri "/assets../.env"] [unique_id "ar3j0nXG1G80tLMYj3ZsNAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:43:14
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:43:10.397414 2026] [security2:error] [pid 29705:tid 29705] [client 136.70.209.133:45442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.healthpointphysicians.co"] [uri "/build../.env"] [unique_id "ar26rnHbI-MWr4U5ET4thQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:34:46
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:34:40.508828 2026] [security2:error] [pid 11370:tid 11370] [client 136.70.209.133:49086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cookes.co"] [uri "/js../.env"] [unique_id "ar2qoF49l8zmkDEO5cdK-gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
KTSTechnology
2026-09-30 23:39:21
(23 hours ago)
Web vulnerability scanning detected by our ISP firewall
Web App Attack
๐ฌ๐ง
WebNiraj
2026-09-30 23:37:45
(23 hours ago)
(htpasswd,mod_security) Login failure/trigger from 136.70.209.133 (US/United States/133.209.70.136.b ...
show more
(htpasswd,mod_security) Login failure/trigger from 136.70.209.133 (US/United States/133.209.70.136.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
SSH
๐ณ๐ฑ
Savvii
2026-09-30 22:24:54
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-30 21:45:52
(1 day ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐ฌ๐ง
Marten Mark
2026-09-30 18:47:00
(1 day ago)
136.70.209.133 - - [30/Sep/2026:18:46:53 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "M ...
show more
136.70.209.133 - - [30/Sep/2026:18:46:53 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
136.70.209.133 - - [30/Sep/2026:18:46:53 +0000] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 110 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
136.70.209.133 - - [30/Sep/2026:18:46:55 +0000] "GET /model/info HTTP/2.0" 404 22981 "https://www.cfi.co/model/info" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
136.70.209.133 - - [30/Sep/2026:18:46:55 +0000] "GET /jhsp5v04tajf6q9yca5r HTTP/2.0" 404 22981 "https://www.cfi.co/jhsp5v04tajf6q9yca5r" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
136.70.209.133 - - [30/Sep/2026:18:46:55 +0000] "GET /z9x8c7v6b5-debug-trigger-www.cfi.co HTTP/2.0" 404 22981 "https://www.cfi.co/z9x8
...
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:04:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:04:49.077551 2026] [security2:error] [pid 20613:tid 20613] [client 136.70.209.133:47808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cmexico.co"] [uri "/.env.development"] [unique_id "ar0lEcGRmYBz0NljNYdpLQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-30 14:37:48
(1 day ago)
136.70.209.133 - - [30/Sep/2026:10:37:47 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 81179 "-" "Mo ...
show more
136.70.209.133 - - [30/Sep/2026:10:37:47 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 81179 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
136.70.209.133 - - [30/Sep/2026:10:37:47 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 81179 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
136.70.209.133 - - [30/Sep/2026:10:37:47 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 81251 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:04:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:04:17.069248 2026] [security2:error] [pid 18996:tid 18996] [client 136.70.209.133:39186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blc2.co"] [uri "/web.config"] [unique_id "ar0W4WYXpQdaULUCmDsGHgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:47:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:47:08.971512 2026] [security2:error] [pid 6666:tid 6666] [client 136.70.209.133:58678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.garanta.co"] [uri "/.env.staging"] [unique_id "ar0S3NzqQWtu2uTeBWypWgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-30 12:32:50
(1 day ago)
(y3) Failed access -byebye- from 136.70.209.133 (US/United States/133.209.70.136.bc.googleuserconten ...
show more
(y3) Failed access -byebye- from 136.70.209.133 (US/United States/133.209.70.136.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 11:56:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.209.133 (133.209.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:56:39.088313 2026] [security2:error] [pid 8013:tid 8013] [client 136.70.209.133:33390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.epetsure.co"] [uri "/.htpasswd"] [unique_id "arz49848D4liVmyMVfkPMAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack