๐ซ๐ท
SpaceHost-Server
2026-09-22 22:16:57
(5 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:16:04
(6 days ago)
Brute-Force
Web App Attack
Anonymous
2026-09-21 07:36:51
(1 week ago)
136.109.132.30 - - [20/Sep/2026:16:39:01 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compa ...
show more
136.109.132.30 - - [20/Sep/2026:16:39:01 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 136.109.132.30
136.109.132.30 - - [20/Sep/2026:16:39:01 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 136.109.132.30
136.109.132.30 - - [20/Sep/2026:16:39:01 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 136.109.132.30
136.109.132.30 - - [20/Sep/2026:16:39:01 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 136.109.132.30
136.109.132.30 - - [20/Sep/2026:16:39:01 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 136.109.132.30
136.109.132.30 - - [20/Sep/2026:16:39:01 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compa
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 06:10:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:10:24.792663 2026] [security2:error] [pid 17035:tid 17035] [client 136.109.132.30:57684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cosmicdebris.org"] [uri "/.git/HEAD"] [unique_id "arDKUBs0kqlRicdK7oFNkwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-09-21 05:28:24
(1 week ago)
2026/09/21 05:28:22 [error] 851147#851147: *20248633 access forbidden by rule, client: 136.109.132.3 ...
show more
2026/09/21 05:28:22 [error] 851147#851147: *20248633 access forbidden by rule, client: 136.109.132.30, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "dev2.wellbin.org"
2026/09/21 05:28:22 [error] 851151#851151: *20248625 access forbidden by rule, client: 136.109.132.30, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "dev2.wellbin.org"
2026/09/21 05:28:23 [error] 851147#851147: *20248665 access forbidden by rule, client: 136.109.132.30, server: fn.binixo.es, request: "GET /admin HTTP/2.0", host: "dev2.wellbin.org"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:10:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:09:56.939386 2026] [security2:error] [pid 18048:tid 18048] [client 136.109.132.30:60960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.humandesignanalysis.org"] [uri "/.env.backup"] [unique_id "arC8JO0Sm99jieWcYHvgFQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:48:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:48:39.661465 2026] [security2:error] [pid 29882:tid 29882] [client 136.109.132.30:52410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.justjunglejuice.org"] [uri "/docker/.env"] [unique_id "arC3J1QggH23nR_1t3n5yQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 04:21:26
(1 week ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:03:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:03:39.402544 2026] [security2:error] [pid 8526:tid 8526] [client 136.109.132.30:39952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hker.org"] [uri "/.env_sample"] [unique_id "arCsm7mJrdUTKBgvSjahwgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:47:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:47:46.806917 2026] [security2:error] [pid 3187:tid 3204] [client 136.109.132.30:35030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.giere.org"] [uri "/.env.local"] [unique_id "arCo4ktJrWe6JJdwU9vixwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:30:30
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:30:24.489145 2026] [security2:error] [pid 22024:tid 22024] [client 136.109.132.30:52934] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.clevelanddental.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.clevelanddental.org"] [uri "/rclone.conf"] [unique_id "arCk0Pn5HzcNDJvc_3vTbwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-09-21 03:21:48
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 136.109.132.30 (US/United States/30.132 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.109.132.30 (US/United States/30.132.109.136.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 03:10:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:10:03.316790 2026] [security2:error] [pid 25686:tid 25686] [client 136.109.132.30:41408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adona.org"] [uri "/userfiles"] [unique_id "arCgC9DLFy_ty2rRL5z2XAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:43:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.132.30 (30.132.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:43:03.128137 2026] [security2:error] [pid 5749:tid 5749] [client 136.109.132.30:38978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uat.equipoperu.org"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "arCZt8lWvFCYUBuDIAB-NwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 21:34:21
(1 week ago)
Logfile match
Web App Attack