๐ซ๐ท
SpaceHost-Server
2026-09-22 22:17:13
(17 hours ago)
Brute-Force
Web App Attack
๐จ๐ฆ
polycoda
2026-09-21 22:27:54
(1 day ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 200 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:16:14
(1 day ago)
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-21 21:38:06
(1 day ago)
2026/09/21 22:37:58 [error] 325888#325888: *1140232 access forbidden by rule, client: 136.110.52.1, ...
show more
2026/09/21 22:37:58 [error] 325888#325888: *1140232 access forbidden by rule, client: 136.110.52.1, server: simetria.org, request: "GET /www2.simetria.org/settings/.env HTTP/2.0", host: "www2.simetria.org", referrer: "https://www2.simetria.org/settings%2F.env"
2026/09/21 22:38:00 [error] 325888#325888: *1140272 access forbidden by rule, client: 136.110.52.1, server: simetria.org, request: "GET /www2.simetria.org/.env HTTP/2.0", host: "www2.simetria.org", referrer: "https://www2.simetria.org/api/uploads/%2e%2e%2f%2e%2e%2f.env"
2026/09/21 22:38:04 [error] 325888#325888: *1140333 access forbidden by rule, client: 136.110.52.1, server: simetria.org, request: "GET /www2.simetria.org/public../.env HTTP/2.0", host: "www2.simetria.org", referrer: "https://www2.simetria.org/public../.env"
show less
Brute-Force
Web App Attack
๐จ๐ฆ
polycoda
2026-09-21 21:35:53
(1 day ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Port Scan
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-21 21:25:06
(1 day ago)
136.110.52.1 - - [21/Sep/2026:21:24:41 +0000] "-" 400 193 "-" "-" "-" edge="136.110.52.1"
136.110.52 ...
show more
136.110.52.1 - - [21/Sep/2026:21:24:41 +0000] "-" 400 193 "-" "-" "-" edge="136.110.52.1"
136.110.52.1 - - [21/Sep/2026:21:24:41 +0000] "-" 400 193 "-" "-" "-" edge="136.110.52.1"
136.110.52.1 - - [21/Sep/2026:21:24:41 +0000] "-" 400 193 "-" "-" "-" edge="136.110.52.1"
136.110.52.1 - - [21/Sep/2026:21:24:41 +0000] "-" 400 193 "-" "-" "-" edge="136.110.52.1"
136.110.52.1 - - [21/Sep/2026:21:24:43 +0000] "-" 400 193 "-" "-" "-" edge="136.110.52.1"
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-21 21:09:53
(1 day ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:48:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.52.1 (1.52.110.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.52.1 (1.52.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:48:36.156593 2026] [security2:error] [pid 31974:tid 31974] [client 136.110.52.1:42062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pnwdso.org"] [uri "/.env.bak"] [unique_id "arGYJL20nCB81KX2h_0BvgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 20:45:47
(1 day ago)
Web Attack Next.js Authorization Bypass Vulnerability
Web App Attack
๐ซ๐ท
LoneRider
2026-09-21 20:15:33
(1 day ago)
[21/Sep/2026:22:15:33.222107 +0200] arGQZWcuEgWNDYBNh4gfCgAAAAo 136.110.52.1 52558 127.0.0.1 7081
[2 ...
show more
[21/Sep/2026:22:15:33.222107 +0200] arGQZWcuEgWNDYBNh4gfCgAAAAo 136.110.52.1 52558 127.0.0.1 7081
[21/Sep/2026:22:15:33.244358 +0200] arGQZUcvBeS2u6UMa97olQAAAAM 136.110.52.1 52588 127.0.0.1 7081
[21/Sep/2026:22:15:33.438116 +0200] arGQZRHOsyTwOgIdFUiCzgAAAAE 136.110.52.1 52620 127.0.0.1 7081
...
show less
Hacking
๐ฉ๐ช
macrob
2026-09-21 19:15:28
(1 day ago)
2026/09/21 19:15:26 [error] 1144019#1144019: *22524154 access forbidden by rule, client: 136.110.52. ...
show more
2026/09/21 19:15:26 [error] 1144019#1144019: *22524154 access forbidden by rule, client: 136.110.52.1, server: fn.binixo.es, request: "GET /.git-credentials HTTP/2.0", host: "sslvpn.wellbin.org"
2026/09/21 19:15:26 [error] 1144019#1144019: *22524155 access forbidden by rule, client: 136.110.52.1, server: fn.binixo.es, request: "GET /.gitconfig HTTP/2.0", host: "sslvpn.wellbin.org"
2026/09/21 19:15:26 [error] 1144019#1144019: *22524156 access forbidden by rule, client: 136.110.52.1, server: fn.binixo.es, request: "GET /.env.example HTTP/2.0", host: "sslvpn.wellbin.org"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:11:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.110.52.1 (1.52.110.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.52.1 (1.52.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:11:11.257870 2026] [security2:error] [pid 3358:tid 3531] [client 136.110.52.1:41034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tnccivic.org"] [uri "/.git/config"] [unique_id "arGBT5j0suhaZo8nj5GtLgAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 18:10:07
(1 day ago)
{"level":"info","ts":1790014202.3210664,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790014202.3210664,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.110.52.1","remote_port":"45152","client_ip":"136.110.52.1","proto":"HTTP/2.0","method":"GET","host":"status.plugfr.org","uri":"/.git/config","headers":{"Accept":["*/*"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"],"Accept-Encoding":["gzip"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.plugfr.org","ech":false}},"bytes_read":0,"user_id":"","duration":0.000203509,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790014202.337676,"logger":"http.log.access.log1","msg":
...
show less
DDoS Attack
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-09-21 16:43:33
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 136.110.52.1 (SG/Singapore/1.52.110.136 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.110.52.1 (SG/Singapore/1.52.110.136.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
LRob
2026-09-21 15:28:01
(2 days ago)
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) ...
show more
This address declares itself a crawler and keeps requesting pages after being refused (HTTP 403/429) and told to stop by robots.txt. A crawler that ignores refusals costs our servers capacity for nothing and is treated as abusive; blocked. Please make it honour robots.txt and the refusals it is given. | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl | path: /.ssh/authorized_keys (+3 more) | 2026-09-21 15:28 UTC
show less
Bad Web Bot