๐ซ๐ท
SpaceHost-Server
2026-09-22 22:17:13
(1 day ago)
Brute-Force
Web App Attack
Anonymous
2026-09-22 01:04:12
(2 days ago)
136.113.114.122 - - [21/Sep/2026:20:04:11 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozill ...
show more
136.113.114.122 - - [21/Sep/2026:20:04:11 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" 136.113.114.122
136.113.114.122 - - [21/Sep/2026:20:04:11 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 136.113.114.122
136.113.114.122 - - [21/Sep/2026:20:04:11 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 136.113.114.122
136.113.114.122 - - [21/Sep/2026:20:04:11 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 136.113.114.122
136.113.114.122 - - [21/Sep/2026:20:04:11 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 136.113.114.122
1
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-09-22 00:48:44
(2 days ago)
2026/09/22 00:48:42 [error] 1144021#1144021: *23224869 access forbidden by rule, client: 136.113.114 ...
show more
2026/09/22 00:48:42 [error] 1144021#1144021: *23224869 access forbidden by rule, client: 136.113.114.122, server: fn.binixo.es, request: "GET /.gitlab-ci.yml HTTP/2.0", host: "iam.smoozy.org"
2026/09/22 00:48:42 [error] 1144021#1144021: *23224869 access forbidden by rule, client: 136.113.114.122, server: fn.binixo.es, request: "GET /.env.backup HTTP/2.0", host: "iam.smoozy.org"
2026/09/22 00:48:42 [error] 1144021#1144021: *23224874 access forbidden by rule, client: 136.113.114.122, server: fn.binixo.es, request: "GET /src/.env HTTP/2.0", host: "iam.smoozy.org"
...
show less
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-22 00:44:34
(2 days ago)
2026/09/22 01:44:32 [error] 325888#325888: *1181960 access forbidden by rule, client: 136.113.114.12 ...
show more
2026/09/22 01:44:32 [error] 325888#325888: *1181960 access forbidden by rule, client: 136.113.114.122, server: simetria.org, request: "GET /.env HTTP/2.0", host: "blog.simetria.org"
136.113.114.122 - - [22/Sep/2026:01:44:32 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
2026/09/22 01:44:32 [error] 325888#325888: *1181975 access forbidden by rule, client: 136.113.114.122, server: simetria.org, request: "GET /agent/.env HTTP/2.0", host: "blog.simetria.org"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:16:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:15:58.225628 2026] [security2:error] [pid 4692:tid 4692] [client 136.113.114.122:55706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ruthbalser.org"] [uri "/.env.bak"] [unique_id "arHIvvyywAoaTEhLLghHUQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:29:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:29:27.701197 2026] [security2:error] [pid 3358:tid 3538] [client 136.113.114.122:41560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.southsideeconomic.org"] [uri "/.git/config"] [unique_id "arG915j0suhaZo8nj5HPQgAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:05:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:05:47.160302 2026] [security2:error] [pid 637:tid 637] [client 136.113.114.122:42514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dc406.org"] [uri "/chatbot/.env"] [unique_id "arG4Sx8EGV2-bcgNtQWxsQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:41:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 136.113.114.122 (122.114.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.113.114.122 (122.114.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:41:06.200307 2026] [security2:error] [pid 23137:tid 23137] [client 136.113.114.122:33918] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.oxyveggietv.com.mroxygen.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.oxyveggietv.com.mroxygen.org"] [uri "/rclone.conf"] [unique_id "arGygn6jvNY8WC6_D863-AAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:16:15
(2 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
factor1
2026-09-21 20:25:03
(2 days ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐ฉ๐ช
macrob
2026-09-21 18:46:51
(2 days ago)
2026/09/21 18:46:49 [error] 1144020#1144020: *22458525 access forbidden by rule, client: 136.113.114 ...
show more
2026/09/21 18:46:49 [error] 1144020#1144020: *22458525 access forbidden by rule, client: 136.113.114.122, server: fn.binixo.es, request: "GET /.env HTTP/2.0", host: "mongodb.pitup.org"
2026/09/21 18:46:49 [error] 1144020#1144020: *22458527 access forbidden by rule, client: 136.113.114.122, server: fn.binixo.es, request: "GET /.aws/credentials HTTP/2.0", host: "mongodb.pitup.org"
2026/09/21 18:46:49 [error] 1144020#1144020: *22458528 access forbidden by rule, client: 136.113.114.122, server: fn.binixo.es, request: "GET /.git/config HTTP/2.0", host: "mongodb.pitup.org"
...
show less
Web App Attack
๐จ๐ฆ
Dunham Support
2026-09-21 18:28:17
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 136.113.114.122 (US/United States/122.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.113.114.122 (US/United States/122.114.113.136.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-21 17:07:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.114.122 (122.114.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:07:05.723383 2026] [security2:error] [pid 21779:tid 21779] [client 136.113.114.122:51200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.qovintheloop.org"] [uri "/.git/config"] [unique_id "arFkOZdCE_eb4IvIlLnV1QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 16:43:24
(2 days ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:30:06
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection