๐ญ๐บ
DumaNet
2026-09-25 05:59:00
(2 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 24. 08:07:13
Source IP: 136.85 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 24. 08:07:13
Source IP: 136.85.73.176
Portion of the log(s):
136.85.73.176 - [24/Sep/2026:08:07:13 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
136.85.73.176 - [24/Sep/2026:08:07:13 +0200] "DELETE /inngest HTTP/1.1" 405 157 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
136.85.73.176 - [24/Sep/2026:08:07:13 +0200] "DELETE /api/inngest HTTP/1.1" 405 157 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
136.85.73.176 - [24/Sep/2026:08:07:13 +0200] "POST /api/fs/exec HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
136.85.73.176 - [24/Sep/2026:08:07:13 +0200] "GET /css../.env HTTP/1.1" 404 153 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
136.85.73.176 - [24/Sep/2026:08:07:13 +0200] "GET /@fs/app/.env?import&raw?? HTTP/1.1" 404 153 "-" "Mozilla
show less
Web App Attack
๐ฎ๐น
paoloartone
2026-09-25 05:00:30
(3 hours ago)
Reverse proxy TCO: 2214 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 24/09/20 ...
show more
Reverse proxy TCO: 2214 richieste malevole bloccate (scan/exploit/brute-force WordPress) il 24/09/2026.
show less
Web App Attack
Hacking
Port Scan
๐ฉ๐ช
4server
2026-09-25 00:40:30
(7 hours ago)
[2026-09-2502:40:27 0200]info[cpaneld]136.85.73.176--\"GET/static/manifest.jsonHTTP/1.1\"FAILEDLOGIN ...
show more
[2026-09-2502:40:27 0200]info[cpaneld]136.85.73.176--\"GET/static/manifest.jsonHTTP/1.1\"FAILEDLOGINcpaneld:loginattemptwithoutusername[2026-09-2502:40:27 0200]info[cpaneld]136.85.73.176--\"GET/webpack-stats.jsonHTTP/1.1\"FAILEDLOGINcpaneld:loginattemptwithoutusername[2026-09-2502:40:28 0200]info[cpaneld]136.85.73.176--\"POST/graphqlHTTP/1.1\"FAILEDLOGINcpaneld:loginattemptwithoutusername[2026-09-2502:40:28 0200]info[cpaneld]136.85.73.176--\"GET/403.shtmlHTTP/1.1\"FAILEDLOGINcpaneld:loginattemptwithoutusername[2026-09-2502:40:28 0200]info[cpaneld]136.85.73.176--\"POST/api/graphqlHTTP/1.1\"FAILEDLOGINcpaneld:loginattemptwithoutusername
show less
Port Scan
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 12:40:06
(20 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:58:31
(23 hours ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ซ๐ท
renzo64
2026-09-24 08:52:04
(23 hours ago)
Domain : MailEnable WebMail
Rule : hack
2026-09-24 08:51:10 ***hidden-privacy*** GET /@fs/root/.aws/ ...
show more
Domain : MailEnable WebMail
Rule : hack
2026-09-24 08:51:10 ***hidden-privacy*** GET /@fs/root/.aws/credentials raw?? 443 - 136.85.73.176 Mozilla/5.0 (compatible; Qwenbot/1.0; https://qwen.alibaba.com/) - 404 0 2 1514 461 202 - -
show less
Hacking
SQL Injection
Brute-Force
๐ซ๐ท
dwmp
2026-09-24 08:19:14
(1 day ago)
[24/Sep/2026:10:19:13.382816 +0200] arTdATse4dFWAqckFWa6KQAAAEM 136.85.73.176 55672 38.242.227.117 7 ...
show more
[24/Sep/2026:10:19:13.382816 +0200] arTdATse4dFWAqckFWa6KQAAAEM 136.85.73.176 55672 38.242.227.117 7081
[24/Sep/2026:10:19:13.567531 +0200] arTdAX2_cs9Qu_ZAEzj9hgAAAAE 136.85.73.176 55698 38.242.227.117 7081
[24/Sep/2026:10:19:13.571578 +0200] arTdAe-VbZug6_kcBRPjOAAAAIo 136.85.73.176 55704 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐ฎ๐น
Inartis
2026-09-24 06:24:54
(1 day ago)
136.85.73.176 - - [24/Sep/2026:08:24:53 +0200] "GET /admin%2F.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 ...
show more
136.85.73.176 - - [24/Sep/2026:08:24:53 +0200] "GET /admin%2F.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
LTM
2026-09-24 06:20:01
(1 day ago)
WebServer - Attempts to exploit
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
McClay
2026-09-24 06:13:36
(1 day ago)
HTTP-404 spam:136.85.73.176 - - [24/Sep/2026:08:13:35 +0200] "GET /asset-manifest.json HTTP/1.1" 404 ...
show more
HTTP-404 spam:136.85.73.176 - - [24/Sep/2026:08:13:35 +0200] "GET /asset-manifest.json HTTP/1.1" 404 1017 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
136.85.73.176 - - [24/Sep/2026:08:13:35 +0200] "GET /edluzualgbpc5vvxx8br HTTP/1.1" 404 1017 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
136.85.73.176 - - [24/Sep/2026:08:13:35 +0200] "GET /z9x8c7v6b5-debug-trigger-www.aapg.xn--kster-jua.it HTTP/1.1" 404 1017 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
136.85.73.176 - - [24/Sep/2026:08:13:35 +0200] "GET /static/manifest.json HTTP/1.1" 404 1017 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
136.85.73.176 - - [24/Sep/2026:08:13:35 +0200] "GET /c76227ngggb8wsy9md21 HTTP/1.1"
...
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
maxpower
2026-09-24 05:59:58
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.85.73.176 (SG/Singapore/176.73.85.13 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.85.73.176 (SG/Singapore/176.73.85.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.85.73.176 - - [24/Sep/2026:07:59:53 +0200] "GET /.aws/credentials HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "136.85.73.176" host=www.villapardi.it
show less
Port Scan
๐ฉ๐ช
Nevermind
2026-09-24 05:43:37
(1 day ago)
136.85.73.176 - - [24/Sep/2026:07:43:36 +0200] "GET /.env HTTP/1.1" 403 5664 "https://www.superdau.i ...
show more
136.85.73.176 - - [24/Sep/2026:07:43:36 +0200] "GET /.env HTTP/1.1" 403 5664 "https://www.superdau.it/.env" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
136.85.73.176 - - [24/Sep/2026:07:43:36 +0200] "GET /.env.production HTTP/1.1" 403 5664 "https://www.superdau.it/.env.production" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
136.85.73.176 - - [24/Sep/2026:07:43:36 +0200] "GET /.env.example HTTP/1.1" 403 5664 "https://www.superdau.it/.env.example" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
136.85.73.176 - - [24/Sep/2026:07:43:36 +0200] "GET /.env.local HTTP/1.1" 403 5664 "https://www.superdau.it/.env.local" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 04:56:22
(1 day ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.85.73.176 - - [24/Sep/2026:06:56:03 +0200] "GET /.env.development HTTP/2.0" 301 505 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-24 03:52:35
(1 day ago)
Accessed trap at '/.aws/credentials'
Web App Attack