π§π·
radardatelecom
2026-10-09 22:27:03
(1 day ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
π©πͺ
TheDjRider
2026-10-09 22:20:58
(1 day ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-10-09T22:20:55.747628021Z. Context: http_status=404, http_status=403
show less
Web App Attack
π©πͺ
Blexyel
2026-10-09 22:11:28
(1 day ago)
136.85.23.137 - - [10/Oct/2026:00:11:27 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "CCBot/2.0 (h ...
show more
136.85.23.137 - - [10/Oct/2026:00:11:27 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 21:45:49
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 136.85.23.137 (137.23.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 136.85.23.137 (137.23.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:45:42.034611 2026] [security2:error] [pid 4616:tid 4616] [client 136.85.23.137:55404] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||oruhu.org|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "oruhu.org"] [uri "/api/fs/read"] [unique_id "aslghqAf2s5bxUCUNStIQQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 21:20:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:19:59.075400 2026] [security2:error] [pid 28819:tid 28819] [client 136.85.23.137:37434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nhglassmakers.org"] [uri "/assets../.env"] [unique_id "aslaf-zj23Mq4-2ku6I9mwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 20:57:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:57:37.976117 2026] [security2:error] [pid 27410:tid 27410] [client 136.85.23.137:46344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalpozzolanassociation.org"] [uri "/css../.env"] [unique_id "aslVQRgB9CJq_ePsxYw3cgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-09 20:40:58
(1 day ago)
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.85.23.137 - - [09/Oct/2026:22:40:56 +0200] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 301 478 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
136.85.23.137 - - [09/Oct/2026:22:40:56 +0200] "GET /userfiles?path=../../.env HTTP/2.0" 403 528 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Bad Web Bot
Web App Attack
π¦πΊ
A.i.D.A.N.N
2026-10-09 20:40:54
(1 day ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 20:27:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:27:42.720106 2026] [security2:error] [pid 15815:tid 15815] [client 136.85.23.137:47322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mvscouts.org"] [uri "/.htpasswd"] [unique_id "aslOPqpN0COE5MXyAV_VWAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
elcruzado.es
2026-10-09 19:21:04
(1 day ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.85.23.137 (SG/Si ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.85.23.137 (SG/Singapore/137.23.85.136.bc.googleusercontent.com)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-09 19:05:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:05:36.590620 2026] [security2:error] [pid 4685:tid 4685] [client 136.85.23.137:57808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moleculardetective.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ask7ABOjJ7PsYxbqN-9H2gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ruusvuu
2026-10-09 18:52:27
(1 day ago)
Automated abuse report: 25 attack/probe requests from Google LLC / SG.
Targeted paths: /api/w/admins ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / SG.
Targeted paths: /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ, /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ, /proc/self/cmdline, /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ, /var/run/secrets/kubernetes.io/serviceaccount/token.
Sample log lines:
[mirassertions] 2026-10-09 11:52:26: 10/9/2026 11:52:26 136.85.23.137 GET /var/run/secrets/kubernetes.io/serviceaccount/token 404 - 1.820 ms -
[mirassertions] 2026-10-09 11:52:26: 10/9/2026 11:52:26 136.85.23.137 GET /proc/self/cgroup 404 - 1.106 ms -
[mirassertions] 2026-10-09 11:52:26: 10/9/2026 11:52:26 136.85.23.137 GET /login 404 - 1.124 ms -
Detected by an automated web-server log monitor.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-09 18:49:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.23.137 (137.23.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:49:46.437409 2026] [security2:error] [pid 29413:tid 29413] [client 136.85.23.137:37844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "minietonrailroad.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ask3Srq6pp6sBX5zQ8yAYgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 18:45:34
(1 day ago)
Fail2Ban apache-noscript
Bad Web Bot
π§πͺ
cmbplf
2026-10-09 18:30:16
(1 day ago)
878 requests with url.path */@fs/*
166 requests with url.path *.aws/*
137 requests with url.path ...
show more
878 requests with url.path */@fs/*
166 requests with url.path *.aws/*
137 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot