๐ซ๐ท
SpaceHost-Server
2026-09-22 22:17:15
(4 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-09-22 01:54:03
(1 day ago)
2026/09/22 01:54:00 [error] 1144022#1144022: *23369196 access forbidden by rule, client: 136.115.193 ...
show more
2026/09/22 01:54:00 [error] 1144022#1144022: *23369196 access forbidden by rule, client: 136.115.193.113, server: fn.binixo.es, request: "GET /z9x8c7v6b5-debug-trigger-admin2.wynspire.org HTTP/2.0", host: "admin2.wynspire.org"
2026/09/22 01:54:00 [error] 1144022#1144022: *23369208 access forbidden by rule, client: 136.115.193.113, server: fn.binixo.es, request: "GET /.env.js HTTP/2.0", host: "admin2.wynspire.org"
2026/09/22 01:54:02 [error] 1144022#1144022: *23369196 access forbidden by rule, client: 136.115.193.113, server: fn.binixo.es, request: "GET /.git/HEAD HTTP/2.0", host: "admin2.wynspire.org"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:27:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:27:24.430060 2026] [security2:error] [pid 9688:tid 9688] [client 136.115.193.113:59256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wgld.cmabiblequizzing.org"] [uri "/.env.prod"] [unique_id "arHZfFIxK26b8Jv4Oq2hhgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-09-22 00:12:51
(1 day ago)
2026/09/22 00:12:49 [error] 1144022#1144022: *23139376 access forbidden by rule, client: 136.115.193 ...
show more
2026/09/22 00:12:49 [error] 1144022#1144022: *23139376 access forbidden by rule, client: 136.115.193.113, server: fn.binixo.es, request: "GET /api/.env HTTP/2.0", host: "preprod.wynspire.org"
2026/09/22 00:12:49 [error] 1144022#1144022: *23139380 access forbidden by rule, client: 136.115.193.113, server: fn.binixo.es, request: "GET /.gitlab-ci.yml HTTP/2.0", host: "preprod.wynspire.org"
2026/09/22 00:12:49 [error] 1144019#1144019: *23139381 access forbidden by rule, client: 136.115.193.113, server: fn.binixo.es, request: "GET /.github/workflows/deploy.yml HTTP/2.0", host: "preprod.wynspire.org"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:10:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:10:23.182597 2026] [security2:error] [pid 22084:tid 22084] [client 136.115.193.113:56726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.towlefarmcommunity.org"] [uri "/.git/config"] [unique_id "arHHbxmWC9LeZ2liTh2aSAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:29:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:29:00.153755 2026] [security2:error] [pid 6752:tid 6752] [client 136.115.193.113:43226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mroxygen.org"] [uri "/.env_1"] [unique_id "arG9vJKOp-Na3FRXNGv25wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:27:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:27:20.208393 2026] [security2:error] [pid 32326:tid 32326] [client 136.115.193.113:57524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.teachachildchangeanation.org"] [uri "/.env.production"] [unique_id "arGvSFBKdpX-V-kGHG72dQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-21 22:16:18
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:18:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:18:21.174709 2026] [security2:error] [pid 1511:tid 1511] [client 136.115.193.113:53412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wordpress.martinka.org"] [uri "/.git/HEAD"] [unique_id "arGfHbf4lg0SVeaOjOYVkAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:20:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:20:41.864253 2026] [security2:error] [pid 2457:tid 2457] [client 136.115.193.113:35176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.steveplunkett.coolwebsites.org"] [uri "/.env.local"] [unique_id "arGRmdo34f9hsphPre8i_AAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:52:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:52:30.192534 2026] [security2:error] [pid 6973:tid 7019] [client 136.115.193.113:43060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.supernumerarios.wizart.org"] [uri "/workspace/.env"] [unique_id "arGK_qvEMth_EtWv56THXwAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 18:49:01
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 18:28:14
(1 day ago)
[Mon Sep 21 20:28:12.656395 2026] [php:error] [pid 1337947] [client 136.115.193.113:44768] script '/ ...
show more
[Mon Sep 21 20:28:12.656395 2026] [php:error] [pid 1337947] [client 136.115.193.113:44768] script '/var/www/11spielerinnen.de/public_html/phpinfo.php' not found or unable to stat
[Mon Sep 21 20:28:12.816564 2026] [php:error] [pid 1365925] [client 136.115.193.113:44782] script '/var/www/11spielerinnen.de/public_html/info.php' not found or unable to stat
[Mon Sep 21 20:28:12.972573 2026] [php:error] [pid 1337947] [client 136.115.193.113:44768] script '/var/www/11spielerinnen.de/public_html/pi.php' not found or unable to stat
[Mon Sep 21 20:28:13.158640 2026] [php:error] [pid 1365957] [client 136.115.193.113:44788] script '/var/www/11spielerinnen.de/public_html/test.php' not found or unable to stat
[Mon Sep 21 20:28:13.368283 2026] [php:error] [pid 1365925] [client 136.115.193.113:44782] script '/var/www/11spielerinnen.de/public_html/i.php' not found or unable to stat
...
show less
Bad Web Bot
๐จ๐ฆ
SoteriaCovenant
2026-09-21 16:56:58
(1 day ago)
Automated probe: /.env.stage on Soteria Global infrastructure. No vulnerable software present.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:31:08
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 136.115.193.113 (113.193.115.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:949110) triggered by 136.115.193.113 (113.193.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:31:00.989506 2026] [security2:error] [pid 31495:tid 31495] [client 136.115.193.113:56490] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.toxicnation.org"] [uri "/userfiles"] [unique_id "arFNtOgTyoBQppxqmzUqbQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack