π²π½
octageeks.com
2026-10-07 04:34:10
(2 hours ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
π§πͺ
taivas.nl
2026-10-07 04:32:46
(2 hours ago)
Many_bad_calls
Web App Attack
π©πͺ
Bedios GmbH
2026-10-07 03:20:41
(3 hours ago)
Keyfile theft attempt
Hacking
πΊπΈ
chronos
2026-10-07 01:32:32
(5 hours ago)
[AUTORAVALT][[06/10/2026 - 22:32:31 -03:00 UTC]
Attack from [Google LLC]
[136.90.77.149][149.77.90.1 ...
show more
[AUTORAVALT][[06/10/2026 - 22:32:31 -03:00 UTC]
Attack from [Google LLC]
[136.90.77.149][149.77.90.136.bc.googleusercontent.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdm]
...
show less
Hacking
Web App Attack
πΊπΈ
chronos
2026-10-07 00:54:17
(5 hours ago)
[AUTORAVALT][[06/10/2026 - 21:54:17 -03:00 UTC]
Attack from [Google LLC]
[136.90.77.149][149.77.90.1 ...
show more
[AUTORAVALT][[06/10/2026 - 21:54:17 -03:00 UTC]
Attack from [Google LLC]
[136.90.77.149][149.77.90.136.bc.googleusercontent.com]
Action: BLocKed
Bad Web Bot -> Webpage scraping (email extraction, content, etc.) crawlers that do not respect robots.txt. Excessive requests and user agent spoofing.
]
...
show less
Bad Web Bot
π³π±
Alt255
2026-10-06 23:08:58
(7 hours ago)
[cb-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 136.90.77.149 - - [07/Oct/2026:01:08:52 +0200] "GET /z9x8c7v6b5-debug-trigger-about.freightlounge.com HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
136.90.77.149 - - [07/Oct/2026:01:08:52 +0200] "GET /register HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.90.77.149 - - [07/Oct/2026:01:08:52 +0200] "GET /signin HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
136.90.77.149 - - [07/Oct/2026:01:08:52 +0
...
show less
Bad Web Bot
Web App Attack
π«π·
Batz
2026-10-06 22:35:35
(8 hours ago)
Automated Web Bot hunting for hidden .env / AI API Credentials
Port Scan
Bad Web Bot
Web App Attack
π«π·
j-tap
2026-10-06 22:09:08
(8 hours ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
πΊπΈ
robotstxt
2026-10-06 20:40:24
(9 hours ago)
136.90.77.149 - - [06/Oct/2026:20:39:22 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 2 "https://hi ...
show more
136.90.77.149 - - [06/Oct/2026:20:39:22 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 2 "https://highcbdfarms.com/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="136.90.77.149"
136.90.77.149 - - [06/Oct/2026:20:39:23 +0000] "GET /.npmrc HTTP/2.0" 403 20 "https://highcbdfarms.com/.npmrc" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-" edge="136.90.77.149"
136.90.77.149 - - [06/Oct/2026:20:39:23 +0000] "GET /.htpasswd HTTP/2.0" 403 20 "https://highcbdfarms.com/.htpasswd" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" edge="136.90.77.149"
136.90.77.149 - - [06/Oct/2026:20:39:24 +0000] "GET /.ssh/id_rsa HTTP/2.0" 403 20 "https://highcbdfarms.com/.ssh/id_rsa" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-" edge="136.90.77.149"
136.90.77.149 - - [06/Oct/2
...
show less
Web App Attack
π§πͺ
taivas.nl
2026-10-06 20:32:09
(10 hours ago)
Bad_requests
Bad Web Bot
πΊπΈ
Blue Pumpkin
2026-10-06 20:30:22
(10 hours ago)
136.90.77.149 - - [06/Oct/2026:20:30:21 +0000] "GET /z9x8c7v6b5-debug-trigger-hey-ai.com HTTP/1.1" 3 ...
show more
136.90.77.149 - - [06/Oct/2026:20:30:21 +0000] "GET /z9x8c7v6b5-debug-trigger-hey-ai.com HTTP/1.1" 302 633 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Brute-Force
π·π΄
clauss
2026-10-06 20:30:15
(10 hours ago)
136.90.77.149 - - [06/Oct/2026:23:30:15 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///ro ...
show more
136.90.77.149 - - [06/Oct/2026:23:30:15 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 404 22214 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
136.90.77.149 - - [06/Oct/2026:23:30:15 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/2.0" 404 22214 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
π³π±
Alt255
2026-10-06 20:28:59
(10 hours ago)
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 136.90.77.149 - - [06/Oct/2026:22:28:52 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
136.90.77.149 - - [06/Oct/2026:22:28:52 +0200] "POST /lib/terminal-xhr.php HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
136.90.77.149 - - [06/Oct/2026:22:28:52 +0200] "GET /dist/.vite/manifest.json HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
136.90.77.149 - - [06/Oct/2026:22:28:52 +0200] "POST /icecoder/lib/terminal-xhr.php HTTP/2.0" 404 1338 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatib
...
show less
Bad Web Bot
Web App Attack
π¦πΊ
clapper
2026-10-06 20:09:33
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 136.90.77.149 (US/United States/149.77.90.136.b ...
show more
(mod_security) mod_security (id:949110) triggered by 136.90.77.149 (US/United States/149.77.90.136.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-06 19:43:16
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.90.77.149 (149.77.90.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.90.77.149 (149.77.90.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:43:11.551922 2026] [security2:error] [pid 923:tid 923] [client 136.90.77.149:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||haywardcarpentry.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "haywardcarpentry.com"] [uri "/z9x8c7v6b5-debug-trigger-haywardcarpentry.com"] [unique_id "asVPT_pD4JT6EYLCHc09awAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack