π©πͺ
Teufel100
2026-10-11 14:07:13
(3 hours ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
π©πͺ
macrob
2026-10-11 13:39:54
(3 hours ago)
2026/10/11 13:39:53 [error] 2449144#2449144: *40331207 access forbidden by rule, client: 136.110.36. ...
show more
2026/10/11 13:39:53 [error] 2449144#2449144: *40331207 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "chat.wynspire.org"
2026/10/11 13:39:53 [error] 2449143#2449143: *40331205 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "chat.wynspire.org"
2026/10/11 13:39:53 [error] 2449143#2449143: *40331216 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /api/.env/public/.env HTTP/2.0", host: "chat.wynspire.org"
...
show less
Web App Attack
π©πͺ
macrob
2026-10-11 08:36:11
(8 hours ago)
2026/10/11 08:36:10 [error] 2401926#2401926: *39619276 access forbidden by rule, client: 136.110.36. ...
show more
2026/10/11 08:36:10 [error] 2401926#2401926: *39619276 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "cache.wynspire.org"
2026/10/11 08:36:10 [error] 2401926#2401926: *39619279 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "cache.wynspire.org"
2026/10/11 08:36:10 [error] 2401926#2401926: *39619275 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /settings%2F.env HTTP/2.0", host: "cache.wynspire.org"
...
show less
Web App Attack
π¦π²
arm osint
2026-10-11 04:40:09
(12 hours ago)
Automated web vulnerability scanning: 420 HTTP 4xx probes for sensitive paths (/%2Fdashboard, /.env. ...
show more
Automated web vulnerability scanning: 420 HTTP 4xx probes for sensitive paths (/%2Fdashboard, /.env.development::$DATA?raw, /.env.local?raw, /.env.production). Detected by Wazuh HIDS rule 31151 on a self-hosted web server.
show less
Web App Attack
Brute-Force
π©πͺ
macrob
2026-10-11 04:32:52
(12 hours ago)
2026/10/11 04:32:50 [error] 2248584#2248584: *39007917 access forbidden by rule, client: 136.110.36. ...
show more
2026/10/11 04:32:50 [error] 2248584#2248584: *39007917 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "beta.wynspire.org"
2026/10/11 04:32:50 [error] 2248582#2248582: *39007921 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "beta.wynspire.org"
2026/10/11 04:32:51 [error] 2248586#2248586: *39007916 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /static../.env HTTP/2.0", host: "beta.wynspire.org"
...
show less
Web App Attack
π©πͺ
Dominik Lysiak
2026-10-11 00:56:45
(16 hours ago)
136.110.36.213 - - [11/Oct/2026:02:56:43 +0200] "GET / HTTP/2.0" 404 179 "-" "Mozilla/5.0 (Windows N ...
show more
136.110.36.213 - - [11/Oct/2026:02:56:43 +0200] "GET / HTTP/2.0" 404 179 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
136.110.36.213 - - [11/Oct/2026:02:56:43 +0200] "GET /43yjwbvra1sgvx1lr577 HTTP/2.0" 404 179 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
136.110.36.213 - - [11/Oct/2026:02:56:43 +0200] "GET /z9x8c7v6b5-debug-trigger-api.campertrader.org HTTP/2.0" 404 179 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
136.110.36.213 - - [11/Oct/2026:02:56:43 +0200] "GET /nsznr1nzig0l37do5tkr HTTP/2.0" 404 179 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
136.110.36.213 - - [11/Oct/2026:02:56:44 +0200] "-" 400 150 "-" "-"
136.110.36.213 - - [11/Oct/2026:02:56:44 +0200]
...
show less
Web App Attack
π¦πΊ
aranguren.org
2026-10-11 00:55:51
(16 hours ago)
136.110.36.213 - - [11/Oct/2026:11:55:50 +1100] "GET /dist/manifest.json HTTP/2.0" 404 1158 "https:/ ...
show more
136.110.36.213 - - [11/Oct/2026:11:55:50 +1100] "GET /dist/manifest.json HTTP/2.0" 404 1158 "https://api.aranguren.org/dist/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
136.110.36.213 - - [11/Oct/2026:11:55:50 +1100] "GET /apxogfi6tu99qmoqx87j HTTP/2.0" 404 1162 "https://api.aranguren.org/apxogfi6tu99qmoqx87j" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
136.110.36.213 - - [11/Oct/2026:11:55:50 +1100] "GET /manifest.json HTTP/2.0" 404 1148 "https://api.aranguren.org/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.36"
...
show less
Bad Web Bot
π©πͺ
macrob
2026-10-11 00:31:25
(16 hours ago)
2026/10/11 00:31:24 [error] 2248587#2248587: *38536223 access forbidden by rule, client: 136.110.36. ...
show more
2026/10/11 00:31:24 [error] 2248587#2248587: *38536223 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /z9x8c7v6b5-debug-trigger-admin.wynspire.org HTTP/2.0", host: "admin.wynspire.org"
2026/10/11 00:31:24 [error] 2248587#2248587: *38536226 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "admin.wynspire.org"
2026/10/11 00:31:24 [error] 2248585#2248585: *38536225 access forbidden by rule, client: 136.110.36.213, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "admin.wynspire.org"
...
show less
Web App Attack
Anonymous
2026-10-11 00:05:19
(17 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
π³π±
middelkoopcc
2026-10-11 00:01:03
(17 hours ago)
2026-10-11 01:59:16 GET /.env [404] && 2026-10-11 01:59:16 GET /public/admin.json [404] && 2026-10-1 ...
show more
2026-10-11 01:59:16 GET /.env [404] && 2026-10-11 01:59:16 GET /public/admin.json [404] && 2026-10-11 01:59:16 GET /gcp-service.json [404] && 182 more within 20 minutes
show less
Web App Attack
π³π±
Alt255
2026-10-10 23:26:39
(17 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.110.36.213 - - [11/Oct/2026:01:26:25 +0200] "GET /userfiles/x?path=../../.env HTTP/2.0" 403 401 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-10 23:06:29
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.36.213 (213.36.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.36.213 (213.36.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:06:21.419534 2026] [security2:error] [pid 31786:tid 31786] [client 136.110.36.213:38258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uhfcfoundation.org"] [uri "/appearance/../../.env"] [unique_id "asrE7RjAeTyvi4-oQZwZXwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-10-10 23:02:39
(18 hours ago)
27.631 requests from untrusted country (1w6d23h)
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-10 22:50:07
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.36.213 (213.36.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.36.213 (213.36.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 18:49:58.731051 2026] [security2:error] [pid 31694:tid 31694] [client 136.110.36.213:39610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tsiwny.org"] [uri "/.htpasswd"] [unique_id "asrBFqfcLzL_qGpmH9JIbwAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
crypto i trust, hold i must
2026-10-10 22:46:12
(18 hours ago)
Web scanner path: /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ
Web App Attack