๐ฌ๐ง
Andrew
2026-10-08 21:06:51
(13 minutes ago)
136.90.66.194 - - [08/Oct/2026:22:06:50 +0100] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 18362 "-" "Moz ...
show more
136.90.66.194 - - [08/Oct/2026:22:06:50 +0100] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 18362 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
136.90.66.194 - - [08/Oct/2026:22:06:50 +0100] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 18362 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
136.90.66.194 - - [08/Oct/2026:22:06:50 +0100] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 18398 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
136.90.66.194 - - [08/Oct/2026:22:06:50 +0100] "GET /@fs/../.env?raw?? HTTP/1.1" 404 20277 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
136.90.66.194 - - [08/Oct/2026:22:06:51 +0100] "GET /@fs/.env?raw&url?? HTTP/1.1" 404 18358 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
136.90.66.194 - - [08/Oct/2026:22:06:51 +0100] "GET /@fs/.env?url&raw?? HTTP/1.1" 404 18358 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.g
...
show less
Hacking
Web App Attack
๐จ๐ญ
Origon
2026-10-08 21:06:26
(13 minutes ago)
http-probing - IP: 136.90.66.194 - time="2026-10-08T23:06:25+02:00" level=info msg="(555f66b4f6a745 ...
show more
http-probing - IP: 136.90.66.194 - time="2026-10-08T23:06:25+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 136.90.66.194 (US/396982) : 4h ban on Ip 136.90.66.194" module=db
show less
Web App Attack
๐ฉ๐ช
Hazzard
2026-10-08 21:01:44
(18 minutes ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-10-08 20:50:02
(30 minutes ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-08 20:32:21
(47 minutes ago)
136.90.66.194 - - [08/Oct/2026:16:32:20 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 45787 "https://lsahom ...
show more
136.90.66.194 - - [08/Oct/2026:16:32:20 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 45787 "https://lsahomesales.com/.ssh/id_rsa" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
136.90.66.194 - - [08/Oct/2026:16:32:21 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 45792 "https://lsahomesales.com/@fs/app/.env?raw??" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.90.66.194 - - [08/Oct/2026:16:32:21 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 45792 "https://lsahomesales.com/@fs/src/.env?raw??" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Web App Attack
๐ณ๐ฑ
Roderic
2026-10-08 20:31:31
(48 minutes ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan
๐ฉ๐ช
kkw
2026-10-08 20:28:01
(52 minutes ago)
[REDACTED] 136.90.66.194 - - [08/Oct/2026:22:28:01 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 3255 "-" " ...
show more
[REDACTED] 136.90.66.194 - - [08/Oct/2026:22:28:01 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 3255 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-08 20:15:50
(1 hour ago)
Wordlist path sweep | method: GET, POST | path: /q546syoo14r9a90222az, /static/manifest.json, /dist/ ...
show more
Wordlist path sweep | method: GET, POST | path: /q546syoo14r9a90222az, /static/manifest.json, /dist/manifest.json (+3 more) | ua: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/), Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36, Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/) (+1 more)
show less
Port Scan
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 20:06:28
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-10-08 20:05:22
(1 hour ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:54:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.90.66.194 (194.66.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.90.66.194 (194.66.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:54:47.145552 2026] [security2:error] [pid 3414:tid 3414] [client 136.90.66.194:55880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lozzy.net"] [uri "/.htpasswd"] [unique_id "asf1B-GPkvpGkehgADcH6wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-08 19:40:01
(1 hour ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-08 19:37:53
(1 hour ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ง๐ช
taivas.nl
2026-10-08 19:32:10
(1 hour ago)
Bad_requests
Bad Web Bot
๐ณ๐ฑ
debestelapp
2026-10-08 19:25:08
(1 hour ago)
Web App Attack