๐ซ๐ท
SpaceHost-Server
2026-09-30 22:16:26
(1 week ago)
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-09-30 17:09:00
(1 week ago)
2026/09/30 17:08:59 [error] 1318206#1318206: *1936278 access forbidden by rule, client: 136.111.139. ...
show more
2026/09/30 17:08:59 [error] 1318206#1318206: *1936278 access forbidden by rule, client: 136.111.139.127, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "cpanel.pitup.org"
2026/09/30 17:08:59 [error] 1318206#1318206: *1936281 access forbidden by rule, client: 136.111.139.127, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "cpanel.pitup.org"
2026/09/30 17:08:59 [error] 1318206#1318206: *1936291 access forbidden by rule, client: 136.111.139.127, server: fn.binixo.es, request: "GET /media../.env HTTP/2.0", host: "cpanel.pitup.org"
...
show less
Web App Attack
๐บ๐ธ
pszsh
2026-09-30 14:59:22
(1 week ago)
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sen ...
show more
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sensitive paths, e.g. /lib/terminal-xhr.php /.ssh/id_ed25519 /.npmrc. Observed by an nginx reputation gate; no credentials or user data involved.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:57:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:57:29.244678 2026] [security2:error] [pid 3994:tid 3994] [client 136.111.139.127:54454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cwvr.org"] [uri "/.env.php.bak"] [unique_id "ar0jWZWSRI1zbGIshZUOYgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 14:00:06
(1 week ago)
$f2bV_matches
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:56:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:56:53.775210 2026] [security2:error] [pid 23316:tid 23316] [client 136.111.139.127:39182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.scoutmountaindistrict.org"] [uri "/.env.php.bak"] [unique_id "ar0VJc2OKeEz2l5EO3yynQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ardexter
2026-09-30 13:53:45
(1 week ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
๐บ๐ธ
technojoe99
2026-09-30 13:52:33
(1 week ago)
Exploit scan from 136.111.139.127. GET /z9x8c7v6b5-debug-trigger-management.cup-of-joe.org HTTP/2.0.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:32:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:32:41.024960 2026] [security2:error] [pid 7100:tid 7100] [client 136.111.139.127:36552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ctjcisenate.org"] [uri "/dist../.env"] [unique_id "ar0PeQz9Tae4DYggx2mjeQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 13:22:50
(1 week ago)
Fail2Ban apache-noscript
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 12:29:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:29:37.880760 2026] [security2:error] [pid 4199:tid 4199] [client 136.111.139.127:45754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sundollsforever.org"] [uri "/files../.env"] [unique_id "ar0Asf1Z5EhScEutvLBn5gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:02:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:02:51.713599 2026] [security2:error] [pid 5950:tid 5950] [client 136.111.139.127:41330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rharano.org"] [uri "/media../.env"] [unique_id "arz6a_QCRAClLIiaIwSN8QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:47:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:47:10.673482 2026] [security2:error] [pid 32515:tid 32515] [client 136.111.139.127:46186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepinesokc.org"] [uri "/uploads../.env"] [unique_id "arz2vuz8c7kGc_ZgZ9LM3AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 11:27:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:27:53.899617 2026] [security2:error] [pid 23731:tid 23731] [client 136.111.139.127:58362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gsrsv.org"] [uri "/build../.env"] [unique_id "arzyOQxp5M3UkaHhZmftrAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:57:57
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 136.111.139.127 (127.139.111.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:949110) triggered by 136.111.139.127 (127.139.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:57:52.349264 2026] [security2:error] [pid 2434:tid 2434] [client 136.111.139.127:32856] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.freedrm.org"] [uri "/static../.env"] [unique_id "arzrMI_nA8Iy6S9x9jjcBAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack