๐ซ๐ท
IRISIO
2026-09-30 08:27:54
(1 hour ago)
scans/SQL injection/spam posts : 14862 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 04:01:13
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.90.72.35 (35.72.90.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.72.35 (35.72.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:01:08.564200 2026] [security2:error] [pid 14199:tid 14199] [client 136.90.72.35:38658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.cfedwest.com|F|2"] [data ".cfedwest.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.cfedwest.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.cfedwest.com"] [unique_id "aryJhEGok7gXpSxuEYosdwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 03:53:16
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฆ๐บ
AWW-Admin
2026-09-30 02:55:34
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.90.72.35 (US/United States/35.72.90 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.90.72.35 (US/United States/35.72.90.136.bc.googleusercontent.com)
show less
SQL Injection
๐จ๐ญ
copestack
2026-09-30 01:30:08
(8 hours ago)
Honeypot hit on ov-4e5936 (fail2ban jail: nginx-compat)
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-30 01:00:16
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.90.72.35 (US/United States/35.72.90 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.90.72.35 (US/United States/35.72.90.136.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
e.fierstra
2026-09-30 00:50:25
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-29 23:46:30
(10 hours ago)
136.90.72.35 - - [29/Sep/2026:23:46:03 +0000] "GET /.git-credentials HTTP/2.0" 403 189 "-" "Mozilla/ ...
show more
136.90.72.35 - - [29/Sep/2026:23:46:03 +0000] "GET /.git-credentials HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.90.72.35 - - [29/Sep/2026:23:46:03 +0000] "GET /.env.js HTTP/2.0" 403 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
136.90.72.35 - - [29/Sep/2026:23:46:03 +0000] "GET /.env.example HTTP/2.0" 403 189 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
136.90.72.35 - - [29/Sep/2026:23:46:03 +0000] "GET /.env.production HTTP/2.0" 403 189 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
136.90.72.35 - - [29/Sep/2026:23:46:03 +0000] "GET /.env.local HTTP/2.0" 403 197 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
...
show less
Web App Attack
๐ซ๐ท
Zundapper
2026-09-29 23:36:50
(10 hours ago)
136.90.72.35 - - [30/Sep/2026:01:36:50 +0200] "GET /panel HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Window ...
show more
136.90.72.35 - - [30/Sep/2026:01:36:50 +0200] "GET /panel HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
136.90.72.35 - - [30/Sep/2026:01:36:50 +0200] "GET /secure HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
136.90.72.35 - - [30/Sep/2026:01:36:50 +0200] "GET /account/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
136.90.72.35 - - [30/Sep/2026:01:36:50 +0200] "GET /console HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
136.90.72.35 - - [30/Sep/2026:01:36:50 +0200] "GET /forgot-password HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
๐ฉ๐ช
LRob
2026-09-29 23:24:12
(11 hours ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.h ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html), Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl (+7 more) | path: /lib/terminal-xhr.php, /.vite/manifest.json, /dist/manifest.json (+15 more)
show less
Bad Web Bot
๐ซ๐ท
regishoussin
2026-09-29 23:08:31
(11 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-29 23:08 UTC.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-29 23:02:29
(11 hours ago)
(PERMBLOCK) 136.90.72.35 (US/United States/District of Columbia/Washington/35.72.90.136.bc.googleuse ...
show more
(PERMBLOCK) 136.90.72.35 (US/United States/District of Columbia/Washington/35.72.90.136.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
Anonymous
2026-09-29 22:56:06
(11 hours ago)
136.90.72.35 - - [30/Sep/2026:00:56:04 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 1 ...
show more
136.90.72.35 - - [30/Sep/2026:00:56:04 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
136.90.72.35 - - [30/Sep/2026:00:56:04 +0200] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 150 "-" "-"
136.90.72.35 - - [30/Sep/2026:00:56:04 +0200] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
136.90.72.35 - - [30/Sep/2026:00:56:04 +0200] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
136.90.72.35 - - [30/Sep/2026:00:56:05 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐ง๐ฌ
HighWay
2026-09-29 22:53:24
(11 hours ago)
136.90.72.35 - - [29/Sep/2026:22:53:21 +0000] "GET /c1oo4iuu89yf1124247i HTTP/1.1" 404 483 "-" "Mozi ...
show more
136.90.72.35 - - [29/Sep/2026:22:53:21 +0000] "GET /c1oo4iuu89yf1124247i HTTP/1.1" 404 483 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
136.90.72.35 - - [29/Sep/2026:22:53:21 +0000] "GET /zordraevwhtwo85y1k0w HTTP/1.1" 404 5577 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
136.90.72.35 - - [29/Sep/2026:22:53:21 +0000] "POST /graphql HTTP/1.1" 404 483 "https://portainer.vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.90.72.35 - - [29/Sep/2026:22:53:21 +0000] "GET /gradle.properties HTTP/1.1" 404 483 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
136.90.72.35 - - [29/Sep/2026:22:53:21 +0000] "POST /api/graphql HTTP/1.1" 404 483 "https://portainer.vhelectronics.com" "Mozilla/5.0 (Windows NT
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-29 22:15:16
(12 hours ago)
136.90.72.35 - - [29/Sep/2026:22:14:16 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25475 "-" "Moz ...
show more
136.90.72.35 - - [29/Sep/2026:22:14:16 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25475 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="136.90.72.35"
136.90.72.35 - - [29/Sep/2026:22:14:21 +0000] "GET /@fs/src/.env?raw?? HTTP/2.0" 403 26836 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="136.90.72.35"
136.90.72.35 - - [29/Sep/2026:22:14:21 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 26836 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="136.90.72.35"
136.90.72.35 - - [29/Sep/2026:22:14:21 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 26836 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="136.90.72.35"
136.90.72.35 - - [29/Sep/2026:22:14:21 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 403 26836 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +http
...
show less
Web App Attack