๐ฑ๐น
Evag Touf
2026-10-08 20:48:59
(3 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.85.19.41 (SG/Sin ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.85.19.41 (SG/Singapore/41.19.85.136.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
dot.mg
2026-10-08 20:44:44
(7 minutes ago)
Scan of vulnerable files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:40:57
(11 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.85.19.41 (41.19.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.19.41 (41.19.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:40:54.171901 2026] [security2:error] [pid 27621:tid 27621] [client 136.85.19.41:58300] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||acsellsre.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acsellsre.com"] [uri "/z9x8c7v6b5-debug-trigger-acsellsre.com"] [unique_id "asf_1udN-KQMpmkHkFfU4gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-10-08 20:35:19
(16 minutes ago)
2026-10-08 20:34:41 GET /static../.env - - 136.85.19.41 HTTP/2 Mozilla/5.0+(compatible;+ChatGLM-Spid ...
show more
2026-10-08 20:34:41 GET /static../.env - - 136.85.19.41 HTTP/2 Mozilla/5.0+(compatible;+ChatGLM-Spider/1.0;++https://zhipuai.cn/) - 301 600
...
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-08 20:20:26
(31 minutes ago)
csagent: score 22.0: 404 noise floor x3, secrets grab x2, php 404 x1; 2 domain(s) in 24s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 20:08:36
(43 minutes ago)
(mod_security) mod_security (id:210730) triggered by 136.85.19.41 (41.19.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.85.19.41 (41.19.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:08:29.908889 2026] [security2:error] [pid 24749:tid 24749] [client 136.85.19.41:45322] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||acmax.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acmax.com"] [uri "/z9x8c7v6b5-debug-trigger-acmax.com"] [unique_id "asf4PZo7Da06yjMKtxF-6wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-08 20:05:20
(46 minutes ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
Anonymous
2026-10-08 19:56:49
(55 minutes ago)
Portscan: TCP/8443 (7x), TCP/8080 (7x), TCP/443, TCP/80
Port Scan
๐ฉ๐ช
snhosting
2026-10-08 19:51:15
(1 hour ago)
136.85.19.41 - - [08/Oct/2026:21:51:05 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 0 "-" "Mo ...
show more
136.85.19.41 - - [08/Oct/2026:21:51:05 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.85.19.41 - - [08/Oct/2026:21:51:05 +0200] "POST / HTTP/2.0" 404 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
136.85.19.41 - - [08/Oct/2026:21:51:05 +0200] "GET /z9x8c7v6b5-debug-trigger-achimherbst.de HTTP/2.0" 404 0 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
136.85.19.41 - - [08/Oct/2026:21:51:05 +0200] "GET /build/manifest.json HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.85.19.41 - - [08/Oct/2026:21:51:05 +0200] "GET /dist/manifest.json HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
Anonymous
2026-10-08 19:50:05
(1 hour ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 19:44:12
(1 hour ago)
(mod_security) mod_security (id:210580) triggered by 136.85.19.41 (41.19.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 136.85.19.41 (41.19.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:44:07.745719 2026] [security2:error] [pid 21984:tid 21984] [client 136.85.19.41:34066] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||achari.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "achari.com"] [uri "/userfiles/x"] [unique_id "asfyh3I_59LwnM_4iDZZugAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-08 19:43:33
(1 hour ago)
excessive HTTP 404 errors
Bad Web Bot
๐ฆ๐บ
AWW-Admin
2026-10-08 19:42:13
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 136.85.19.41 (SG/Singapore/41.19.85.136 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.85.19.41 (SG/Singapore/41.19.85.136.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-10-08 19:40:02
(1 hour ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
dwmp
2026-10-08 19:28:31
(1 hour ago)
Url probing: /46uzahqf15veinb70qgs
Web App Attack