๐ฉ๐ช
macrob
2026-09-18 13:25:32
(2 hours ago)
2026/09/18 13:25:31 [error] 3753132#3753132: *11759529 access forbidden by rule, client: 136.110.16. ...
show more
2026/09/18 13:25:31 [error] 3753132#3753132: *11759529 access forbidden by rule, client: 136.110.16.143, server: fn.binixo.es, request: "GET /frontend/.env HTTP/2.0", host: "admin.wellbin.org"
2026/09/18 13:25:31 [error] 3753134#3753134: *11759531 access forbidden by rule, client: 136.110.16.143, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "admin.wellbin.org"
2026/09/18 13:25:31 [error] 3753134#3753134: *11759532 access forbidden by rule, client: 136.110.16.143, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "admin.wellbin.org"
...
show less
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-18 13:18:11
(2 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-18T13:18:10.529347785Z. Context: http_status=302
show less
Web App Attack
Anonymous
2026-09-18 11:22:03
(4 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
melroy89
2026-09-18 09:29:10
(6 hours ago)
136.110.16.143 - - [18/Sep/2026:11:28:56 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Linux; And ...
show more
136.110.16.143 - - [18/Sep/2026:11:28:56 +0200] "GET / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36" "accounting.libreweb.org" 0.000
136.110.16.143 - - [18/Sep/2026:11:28:56 +0200] "GET /api/v1/settings HTTP/1.1" 403 9 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "accounting.libreweb.org" 0.000
136.110.16.143 - - [18/Sep/2026:11:28:56 +0200] "GET /z9x8c7v6b5-debug-trigger-accounting.libreweb.org HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "accounting.libreweb.org" 0.000
136.110.16.143 - - [18/Sep/2026:11:28:56 +0200] "GET /__/firebase/init.json HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "accounting.libreweb.org" 0.000
136.110.16.143 - - [18/Sep/2026:11:28:56 +0200] "POST / HTTP/1.1" 403 9 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "accounting.libreweb.org" 0.000
136.110.16.
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-09-18 09:10:02
(6 hours ago)
2026/09/18 09:10:00 [error] 3753132#3753132: *11084329 access forbidden by rule, client: 136.110.16. ...
show more
2026/09/18 09:10:00 [error] 3753132#3753132: *11084329 access forbidden by rule, client: 136.110.16.143, server: fn.binixo.es, request: "GET /.ssh/id_rsa HTTP/2.0", host: "account.wellbin.org"
2026/09/18 09:10:00 [error] 3753132#3753132: *11084330 access forbidden by rule, client: 136.110.16.143, server: fn.binixo.es, request: "GET /.idea/WebServers.xml HTTP/2.0", host: "account.wellbin.org"
2026/09/18 09:10:00 [error] 3753132#3753132: *11084331 access forbidden by rule, client: 136.110.16.143, server: fn.binixo.es, request: "GET /.vscode/launch.json HTTP/2.0", host: "account.wellbin.org"
...
show less
Web App Attack
๐จ๐ฆ
polycoda
2026-09-18 05:54:05
(9 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐ง๐ท
Peregrine
2026-09-18 03:09:32
(12 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 136.110.16.143 172.69.165.76 - - [16/Sep/2026:22:56:53 -0 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 136.110.16.143 172.69.165.76 - - [16/Sep/2026:22:56:53 -0300] "GET /.github/.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐ง๐ช
voormedia
2026-09-18 01:28:13
(14 hours ago)
Accessed trap at '/docker-compose.yml'
Web App Attack
Anonymous
2026-09-17 23:53:31
(15 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ช๐ธ
el-brujo
2026-09-17 23:32:52
(16 hours ago)
18/Sep/2026:01:32:51.789434 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
18/Sep/2026:01:32:51.789434 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 136.110.16.143] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%252f found within REQUEST_URI_RAW: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/@fs/..%2f..%2f..%2f..%2f..
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-17 22:32:25
(17 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:15:26
(17 hours ago)
Brute-Force
Web App Attack
๐ท๐บ
olegio
2026-09-17 18:41:32
(20 hours ago)
136.110.16.143 - - [17/Sep/2026:18:41:30 +0000] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 146 "-" "Mozi ...
show more
136.110.16.143 - - [17/Sep/2026:18:41:30 +0000] "GET /@fs/src/.env?raw?? HTTP/1.1" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
136.110.16.143 - - [17/Sep/2026:18:41:31 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-17 18:30:24
(21 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-17T18:30:21.157403431Z. Context: http_status=404
show less
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-17 16:14:02
(23 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack