๐ง๐ท
Halux
2026-10-08 22:35:42
(8 minutes ago)
136.85.0.78 Probing protected path or service
Web App Attack
๐บ๐ธ
mnsf
2026-10-08 22:05:34
(38 minutes ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-08 22:01:03
(43 minutes ago)
excessive HTTP 404 errors
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-10-08 22:00:22
(43 minutes ago)
Auto-ban: >3000 req/min op 2026-10-08
Web App Attack
SSH
Hacking
๐ฉ๐ช
palzer.IT
2026-10-08 21:56:25
(47 minutes ago)
Fail2ban automatic report for plesk-apache-badbot: 136.85.0.78 - - [08/Oct/2026:23:55:51 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 136.85.0.78 - - [08/Oct/2026:23:55:51 +0200] GET /dist../.env [DOMAIN_REMOVED] 404 58279 [DOMAIN_REMOVED] CCBot/2.0 ([DOMAIN_REMOVED]
show less
Bad Web Bot
๐ฉ๐ช
big-cloud.nl
2026-10-08 21:41:47
(1 hour ago)
Try to access /settings%2F.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 21:37:23
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 136.85.0.78 (78.0.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.0.78 (78.0.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:37:20.071716 2026] [security2:error] [pid 24933:tid 24937] [client 136.85.0.78:54092] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sandbarsteve.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sandbarsteve.com"] [uri "/z9x8c7v6b5-debug-trigger-sandbarsteve.com"] [unique_id "asgNEA_yKxWC4ElF0DaJHgAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 21:11:44
(1 hour ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.85.0.78 - - [08/Oct/2026:23:11:42 +0200] "GET /.ssh/id_rsa HTTP/2.0" 301 468 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-10-08 20:23:35
(2 hours ago)
env leak on sammamish.online/admin/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:19:36
(2 hours ago)
(mod_security) mod_security (id:210580) triggered by 136.85.0.78 (78.0.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 136.85.0.78 (78.0.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:19:32.177783 2026] [security2:error] [pid 19494:tid 19494] [client 136.85.0.78:45830] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||samimartin.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "samimartin.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "asf61HlFYNc1XEBSdR5NKwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-08 20:15:08
(2 hours ago)
Web App Attack
Anonymous
2026-10-08 19:56:54
(2 hours ago)
Portscan: TCP/80, TCP/8080 (3x), TCP/8443 (3x), TCP/443
Port Scan
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-08 19:51:13
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 19:47:41
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.85.0.78 (78.0.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.0.78 (78.0.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:47:34.815806 2026] [security2:error] [pid 30748:tid 30766] [client 136.85.0.78:42146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||salvoni.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salvoni.com"] [uri "/z9x8c7v6b5-debug-trigger-salvoni.com"] [unique_id "asfzVvI8Pf3SxvWBBX04QwAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 19:30:09
(3 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection