๐ฉ๐ช
macrob
2026-10-11 07:57:36
(3 hours ago)
2026/10/11 07:57:35 [error] 2401929#2401929: *39511018 access forbidden by rule, client: 136.110.121 ...
show more
2026/10/11 07:57:35 [error] 2401929#2401929: *39511018 access forbidden by rule, client: 136.110.121.238, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "backend.wellbin.org"
2026/10/11 07:57:35 [error] 2401929#2401929: *39511019 access forbidden by rule, client: 136.110.121.238, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "backend.wellbin.org"
2026/10/11 07:57:35 [error] 2401924#2401924: *39511032 access forbidden by rule, client: 136.110.121.238, server: fn.binixo.es, request: "GET /.ssh/id_ed25519 HTTP/2.0", host: "backend.wellbin.org"
...
show less
Web App Attack
๐ฆ๐ฒ
arm osint
2026-10-11 04:55:34
(6 hours ago)
Automated web vulnerability scanning: 450 HTTP 4xx probes for sensitive paths (/.bash_profile, /.doc ...
show more
Automated web vulnerability scanning: 450 HTTP 4xx probes for sensitive paths (/.bash_profile, /.docker/config.json, /.env, /.env.production). Detected by Wazuh HIDS rule 31151 on a self-hosted web server.
show less
Web App Attack
Brute-Force
๐ช๐ธ
beats
2026-10-11 03:37:10
(7 hours ago)
Reported by CrowdSec
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-10-11 03:12:06
(7 hours ago)
136.110.121.238 - - [11/Oct/2026:05:12:05 +0200] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 4 ...
show more
136.110.121.238 - - [11/Oct/2026:05:12:05 +0200] "GET /cache/original/%2e%2e/%2e%2e/.env HTTP/2.0" 404 179 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)"
136.110.121.238 - - [11/Oct/2026:05:12:05 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 179 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
136.110.121.238 - - [11/Oct/2026:05:12:06 +0200] "GET /.env.old HTTP/2.0" 404 179 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
Anonymous
2026-10-11 01:50:06
(9 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
macrob
2026-10-11 01:45:41
(9 hours ago)
2026/10/11 01:45:39 [error] 2248585#2248585: *38675912 access forbidden by rule, client: 136.110.121 ...
show more
2026/10/11 01:45:39 [error] 2248585#2248585: *38675912 access forbidden by rule, client: 136.110.121.238, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "account.wellbin.org"
2026/10/11 01:45:39 [error] 2248585#2248585: *38675915 access forbidden by rule, client: 136.110.121.238, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "account.wellbin.org"
2026/10/11 01:45:40 [error] 2248585#2248585: *38675901 access forbidden by rule, client: 136.110.121.238, server: fn.binixo.es, request: "GET /static//.env HTTP/2.0", host: "account.wellbin.org"
...
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-11 01:41:35
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ธ๐ช
ability6511
2026-10-11 01:30:22
(9 hours ago)
CrowdSec detected probing for sensitive files or configuration paths on a web application. Scenario= ...
show more
CrowdSec detected probing for sensitive files or configuration paths on a web application. Scenario=crowdsecurity/http-sensitive-files. Events=5. Service=http. First seen=2026-10-11T01:30:22+00:00.
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-10-11 01:20:23
(9 hours ago)
136.110.121.238 - - [11/Oct/2026:01:19:40 +0000] "GET /wp-includes/js/dist/script-modules/interactiv ...
show more
136.110.121.238 - - [11/Oct/2026:01:19:40 +0000] "GET /wp-includes/js/dist/script-modules/interactivity/index.min.js?ver=efaa5193bbad9c60ffd1 HTTP/2.0" 403 15118 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="136.110.121.238"
136.110.121.238 - - [11/Oct/2026:01:19:41 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 15118 "https://wppodcast.org/dist/.vite/manifest.json" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="136.110.121.238"
136.110.121.238 - - [11/Oct/2026:01:19:41 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 15118 "https://wppodcast.org/.vite/manifest.json" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="136.110.121.238"
136.110.121.238 - - [11/Oct/2026:01:19:41 +0000] "GET /dist/manifest.json HTTP/2.0" 403 15118 "https://wppodcast.org/dist/manifest.json" "Mozilla/5.0 (X1
...
show less
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-10-11 01:19:30
(9 hours ago)
Web application probing for unlinked paths and hidden files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-11 01:16:28
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.121.238 (238.121.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.121.238 (238.121.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:16:22.954395 2026] [security2:error] [pid 2602:tid 2602] [client 136.110.121.238:52240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisk.org"] [uri "/.git/config"] [unique_id "asrjZhWfXeuFgxn3aAGHKwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-11 01:05:09
(9 hours ago)
Web App Attack
๐บ๐ธ
kosada.com
2026-10-11 00:55:16
(10 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /@fs/app/.env.local?import&raw?? (HT ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /@fs/app/.env.local?import&raw?? (HTTP/2.0 port 443, user agent: "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:52:47
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.121.238 (238.121.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.121.238 (238.121.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:52:41.055730 2026] [security2:error] [pid 3965:tid 3965] [client 136.110.121.238:41540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uhfcfoundation.org"] [uri "/static/../../../a/../../../../.env"] [unique_id "asrd2cBe-aycz2rQDD30xgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-11 00:50:01
(10 hours ago)
Excessive multi-domain requests
Brute-Force