๐ฉ๐ช
macrob
2026-09-19 15:14:23
(4 hours ago)
2026/09/19 15:14:22 [error] 192277#192277: *15341073 access forbidden by rule, client: 136.108.120.2 ...
show more
2026/09/19 15:14:22 [error] 192277#192277: *15341073 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.aws/credentials HTTP/2.0", host: "demo.wellbin.org"
2026/09/19 15:14:22 [error] 192277#192277: *15341073 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.git/config HTTP/2.0", host: "demo.wellbin.org"
2026/09/19 15:14:22 [error] 192277#192277: *15341074 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.aws/config HTTP/2.0", host: "demo.wellbin.org"
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-09-19 11:58:32
(7 hours ago)
2026/09/19 11:58:31 [error] 31032#31032: *14846740 access forbidden by rule, client: 136.108.120.226 ...
show more
2026/09/19 11:58:31 [error] 31032#31032: *14846740 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "cpanel.wellbin.org"
2026/09/19 11:58:31 [error] 31032#31032: *14846741 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /dist/.env HTTP/2.0", host: "cpanel.wellbin.org"
2026/09/19 11:58:31 [error] 31035#31035: *14846745 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "cpanel.wellbin.org"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:15:33
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.120.226 (226.120.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.120.226 (226.120.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:15:28.369477 2026] [security2:error] [pid 23837:tid 23837] [client 136.108.120.226:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nyemdr.org"] [uri "/.git/HEAD"] [unique_id "aq5u0LKF6UKY4E9-EpL2igAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:29:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.120.226 (226.120.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.120.226 (226.120.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:29:55.901571 2026] [security2:error] [pid 15619:tid 15619] [client 136.108.120.226:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.helpsavepets.org"] [uri "/admin/.env"] [unique_id "aq5kI-VDP9rT5q6Pj60czgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:08:25
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.108.120.226 (226.120.108.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.108.120.226 (226.120.108.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:08:20.080337 2026] [security2:error] [pid 31610:tid 31610] [client 136.108.120.226:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/.env.example"] [unique_id "aq5fFCvA87d_DC_L3k52mQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-19 10:00:05
(9 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-09-19 07:07:43
(12 hours ago)
2026/09/19 07:07:42 [error] 31033#31033: *14068353 access forbidden by rule, client: 136.108.120.226 ...
show more
2026/09/19 07:07:42 [error] 31033#31033: *14068353 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "console.wellbin.org"
2026/09/19 07:07:42 [error] 31034#31034: *14068354 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.git/config HTTP/2.0", host: "console.wellbin.org"
2026/09/19 07:07:42 [error] 31033#31033: *14068356 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.env HTTP/2.0", host: "console.wellbin.org"
...
show less
Web App Attack
๐ช๐ธ
beats
2026-09-19 00:03:56
(19 hours ago)
Reported by CrowdSec
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 21:59:13
(21 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
melroy89
2026-09-18 21:06:57
(22 hours ago)
136.108.120.226 - - [18/Sep/2026:23:06:49 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Linux; An ...
show more
136.108.120.226 - - [18/Sep/2026:23:06:49 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36" "back.libreweb.org" 0.000
136.108.120.226 - - [18/Sep/2026:23:06:49 +0200] "GET /__/firebase/init.json HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "back.libreweb.org" 0.000
136.108.120.226 - - [18/Sep/2026:23:06:49 +0200] "GET /firebase-config.json HTTP/1.1" 403 9 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "back.libreweb.org" 0.000
136.108.120.226 - - [18/Sep/2026:23:06:49 +0200] "POST / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "back.libreweb.org" 0.000
136.108.120.226 - - [18/Sep/2026:23:06:49 +0200] "GET /api/v1/config HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" "back.libreweb.org" 0.000
13
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-09-18 20:31:22
(23 hours ago)
2026/09/18 20:31:20 [error] 3927478#3927478: *12842305 access forbidden by rule, client: 136.108.120 ...
show more
2026/09/18 20:31:20 [error] 3927478#3927478: *12842305 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /admin/.env HTTP/2.0", host: "aws.wellbin.org"
2026/09/18 20:31:20 [error] 3927483#3927483: *12842308 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.aws/config HTTP/2.0", host: "aws.wellbin.org"
2026/09/18 20:31:20 [error] 3927478#3927478: *12842309 access forbidden by rule, client: 136.108.120.226, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "aws.wellbin.org"
...
show less
Web App Attack
๐บ๐ธ
chrisj
2026-09-18 20:31:08
(23 hours ago)
[Fri Sep 18 20:31:07.392999 2026] [proxy_fcgi:error] [pid 52392:tid 52429] [remote 136.108.120.226:4 ...
show more
[Fri Sep 18 20:31:07.392999 2026] [proxy_fcgi:error] [pid 52392:tid 52429] [remote 136.108.120.226:42110] AH01071: Got error 'Primary script unknown'
[Fri Sep 18 20:31:07.576003 2026] [proxy_fcgi:error] [pid 52392:tid 52433] [remote 136.108.120.226:42110] AH01071: Got error 'Primary script unknown'
[Fri Sep 18 20:31:07.663748 2026] [proxy_fcgi:error] [pid 52392:tid 52432] [remote 136.108.120.226:42110] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ซ๐ท
Nicos
2026-09-18 19:42:24
(1 day ago)
2026-09-18T21:42:23.579388+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "d ...
show more
2026-09-18T21:42:23.579388+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "domain_url": "Redacted", "event": "/.aws/credentials", "host": "Redacted", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 151284, "remote": "136.108.120.226", "request_id": "91252022a3984d2c96ef3fd58b188e57", "runtime": 39, "schema_name": "public", "scheme": "https", "status": 404, "timestamp": "2026-09-18T19:42:23.579154", "user": "", "user_agent": "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"}
2026-09-18T21:42:23.591856+02:00 PhoenixNas 4b557cefc297[346903]: {"auth_via": "unauthenticated", "domain_url": "Redacted", "event": "/.git/config", "host": "Redacted", "level": "info", "logger": "authentik.asgi", "method": "GET", "pid": 151284, "remote": "136.108.120.226", "request_id": "faa1760717754a638fbd3456f137218f", "runtime": 36, "schema_name": "public", "scheme": "https", "status": 404, "timestam
...
show less
Hacking
Brute-Force
Anonymous
2026-09-18 18:59:20
(1 day ago)
Aggressive web scan
Web App Attack
๐ฆ๐น
Renรฉ Hickersberger
2026-09-18 18:53:44
(1 day ago)
malicious bot detected: violations="ignored-robots-policy"; user_agent="Mozilla/5.0 (compatible; Mis ...
show more
malicious bot detected: violations="ignored-robots-policy"; user_agent="Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
show less
Bad Web Bot