๐บ๐ธ
TPI-Abuse
2026-10-07 18:58:33
(20 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.70.74.218 (218.74.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.74.218 (218.74.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:58:25.464472 2026] [security2:error] [pid 27216:tid 27216] [client 136.70.74.218:35978] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pizzadata.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pizzadata.com"] [uri "/z9x8c7v6b5-debug-trigger-pizzadata.com"] [unique_id "asaWUak9WpdPoKfA3BplTAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-07 18:50:08
(28 minutes ago)
Web App Attack
๐ง๐ช
voormedia
2026-10-07 18:29:13
(49 minutes ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2026-10-07 18:21:04
(57 minutes ago)
Flagged as abuse by IisGuard automated detection (tier L5, score 90/100). Reasons: Reputation=1, Bad ...
show more
Flagged as abuse by IisGuard automated detection (tier L5, score 90/100). Reasons: Reputation=1, BadPath=22,1, Diversity=10, CanaryOverride=90.
show less
Web App Attack
Bad Web Bot
๐ช๐ธ
robotstxt
2026-10-07 17:33:21
(1 hour ago)
136.70.74.218 - - [07/Oct/2026:17:32:38 +0000] "GET /z9x8c7v6b5-debug-trigger-mariaplazacarrasco.com ...
show more
136.70.74.218 - - [07/Oct/2026:17:32:38 +0000] "GET /z9x8c7v6b5-debug-trigger-mariaplazacarrasco.com HTTP/2.0" 403 51534 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="136.70.74.218"
136.70.74.218 - - [07/Oct/2026:17:32:38 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 49889 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="136.70.74.218"
136.70.74.218 - - [07/Oct/2026:17:32:38 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 49895 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="136.70.74.218"
136.70.74.218 - - [07/Oct/2026:17:32:38 +0000] "GET /build/manifest.json HTTP/2.0" 403 49918 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="136.70.74.218"
136.70.74.218 - - [07/Oct/2026:17:32:38 +0000] "GET /dist/manifest.j
...
show less
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-10-07 16:10:04
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.70.74.218 (US/United States/218.74. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.70.74.218 (US/United States/218.74.70.136.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
IRISIO
2026-10-07 16:02:53
(3 hours ago)
scans/SQL injection/spam posts : 54 queries
Web App Attack
SQL Injection
๐ฌ๐ง
Aetherweb Ark
2026-10-07 15:55:23
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.70.74.218 (US/United States/218.74.70.136.b ...
show more
(mod_security) mod_security (id:949110) triggered by 136.70.74.218 (US/United States/218.74.70.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ซ๐ท
david.houstin
2026-10-07 15:53:36
(3 hours ago)
136.70.74.218 - - [07/Oct/2026:17:53:33 +0200] "GET /document.php?modulepart=systemtools&file=../con ...
show more
136.70.74.218 - - [07/Oct/2026:17:53:33 +0200] "GET /document.php?modulepart=systemtools&file=../conf/conf.php&hashp=shared HTTP/2.0" 404 38 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
136.70.74.218 - - [07/Oct/2026:17:53:33 +0200] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/2.0" 404 264 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
136.70.74.218 - - [07/Oct/2026:17:53:33 +0200] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../proc/self/environ HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
136.70.74.218 - - [07/Oct/2026:17:53:33 +0200] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
136.70.74.218 - - [07/Oct/2026:17:53:33 +0200] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron HTTP/2.0"
...
show less
Web App Attack
Bad Web Bot
Anonymous
2026-10-07 15:44:49
(3 hours ago)
Fail2Ban apache-noscript
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 15:40:08
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.74.218 (218.74.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.74.218 (218.74.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:40:04.276113 2026] [security2:error] [pid 25179:tid 25179] [client 136.70.74.218:44676] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grasslakepizzatime.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grasslakepizzatime.com"] [uri "/z9x8c7v6b5-debug-trigger-grasslakepizzatime.com"] [unique_id "asZn1LKzQz0bi4cith0_pAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-07 15:30:37
(3 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-07 15:28:42
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-10-07 15:21:36
(3 hours ago)
136.70.74.218 - - [07/Oct/2026:17:21:31 +0200] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+ ...
show more
136.70.74.218 - - [07/Oct/2026:17:21:31 +0200] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 200 4327 "https://free-reseau.fr/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
136.70.74.218 - - [07/Oct/2026:17:21:32 +0200] "GET /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 200 4322 "https://free-reseau.fr/cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
136.70.74.218 - - [07/Oct/2026:17:21:35 +0200] "GET /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 200 4323 "https://free-reseau.fr/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
show less
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-07 15:07:07
(4 hours ago)
2026/10/07 16:07:00 [error] 4060693#4060693: *894487 access forbidden by rule, client: 136.70.74.218 ...
show more
2026/10/07 16:07:00 [error] 4060693#4060693: *894487 access forbidden by rule, client: 136.70.74.218, server: feminina.eu, request: "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0", host: "feminina.eu"
2026/10/07 16:07:04 [error] 4060693#4060693: *894524 access forbidden by rule, client: 136.70.74.218, server: feminina.eu, request: "GET /cache/original/%2e%2e/.env HTTP/2.0", host: "feminina.eu"
2026/10/07 16:07:06 [error] 4060693#4060693: *894531 access forbidden by rule, client: 136.70.74.218, server: feminina.eu, request: "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0", host: "feminina.eu"
show less
Brute-Force
Web App Attack