🇺🇸
Secure Gateway®️
2026-09-11 22:00:22
(7 hours ago)
Report By Secure Gateway Security Team: SQL Injection Attempt Detected
Web App Attack
🇺🇸
ALSCO®️
2026-09-11 22:00:22
(7 hours ago)
Report By ALSCO Security Team: Unsolicited Connection Attempt
Web App Attack
🇧🇪
cmbplf
2026-09-11 21:39:42
(7 hours ago)
639 requests with url.path */@fs/*
232 requests with url.path */proc/*
185 requests with url.path ...
show more
639 requests with url.path */@fs/*
232 requests with url.path */proc/*
185 requests with url.path *.ssh/*
134 requests with url.path *.aws/*
show less
Brute-Force
Bad Web Bot
🇳🇿
Antinson
2026-09-11 21:39:18
(7 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇩🇪
Marc
2026-09-11 20:11:22
(9 hours ago)
136.70.75.6 - - [11/Sep/2026:22:11:22 +0200] "GET /rclone.conf HTTP/2.0" 404 291 "-" "Mozilla/5.0 (c ...
show more
136.70.75.6 - - [11/Sep/2026:22:11:22 +0200] "GET /rclone.conf HTTP/2.0" 404 291 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 136.70.75.6 - - [11/Sep/2026:22:11:22 +0200] "GET /login HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0" 136.70.75.6 - - [11/Sep/2026:22:11:22 +0200] "GET /dashboard HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.0"
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-11 19:38:17
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:38:11.200578 2026] [security2:error] [pid 18465:tid 18465] [client 136.70.75.6:56166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "altruaglobalsolutions.com"] [uri "/@fs/.env"] [unique_id "aqRYo5tmmgSkLSxGB0pMEwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:18:03
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:17:56.078997 2026] [security2:error] [pid 6711:tid 6711] [client 136.70.75.6:37308] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||altered-egos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "altered-egos.com"] [uri "/z9x8c7v6b5-debug-trigger-altered-egos.com"] [unique_id "aqRT5G6QaqNPb8FnejEwwwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:00:03
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:59:57.247478 2026] [security2:error] [pid 15567:tid 15567] [client 136.70.75.6:33608] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alsetsystems.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alsetsystems.com"] [uri "/rclone.conf"] [unique_id "aqRPrWA4cMImbw3A_ZZltwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 18:39:20
(10 hours ago)
136.70.75.6 - - [11/Sep/2026:20:39:19 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Andro ...
show more
136.70.75.6 - - [11/Sep/2026:20:39:19 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
136.70.75.6 - - [11/Sep/2026:20:39:19 +0200] "GET /login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
136.70.75.6 - - [11/Sep/2026:20:39:19 +0200] "GET /auth/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
136.70.75.6 - - [11/Sep/2026:20:39:19 +0200] "GET /rclone.conf HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
136.70.75.6 - - [11/Sep/2026:20:39:19 +0200] "GET /signin HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
136.70.75.6 - - [1
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 18:07:47
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:07:41.272640 2026] [security2:error] [pid 22176:tid 22176] [client 136.70.75.6:44980] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alpinexport.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alpinexport.com"] [uri "/z9x8c7v6b5-debug-trigger-alpinexport.com"] [unique_id "aqRDbeg2jTyURZIKc2M5SwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-11 18:05:34
(11 hours ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 18:05:02
(11 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:43:51
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.75.6 (6.75.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:43:47.376275 2026] [security2:error] [pid 17143:tid 17143] [client 136.70.75.6:58668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alphadyne.com"] [uri "/files../.env"] [unique_id "aqQ903bvtfjhy9qZNj3C3wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
Origon
2026-09-11 17:31:24
(11 hours ago)
http-path-traversal-probing - IP: 136.70.75.6 - time="2026-09-11T19:31:24+02:00" level=info msg="(5 ...
show more
http-path-traversal-probing - IP: 136.70.75.6 - time="2026-09-11T19:31:24+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-path-traversal-probing by ip 136.70.75.6 (US/396982) : 4h ban on Ip 136.70.75.6" module=db
show less
Web App Attack
🇫🇷
masterguru
2026-09-11 17:29:48
(11 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot