๐ซ๐ท
SpaceHost-Server
2026-10-09 22:16:12
(3 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-10-09 21:11:12
(5 hours ago)
2026/10/09 21:11:10 [error] 1808837#1808837: *34927878 access forbidden by rule, client: 136.70.247. ...
show more
2026/10/09 21:11:10 [error] 1808837#1808837: *34927878 access forbidden by rule, client: 136.70.247.240, server: fn.binixo.es, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "auth.pitup.org"
2026/10/09 21:11:10 [error] 1808837#1808837: *34927883 access forbidden by rule, client: 136.70.247.240, server: fn.binixo.es, request: "GET /.vite/manifest.json HTTP/2.0", host: "auth.pitup.org"
2026/10/09 21:11:10 [error] 1808837#1808837: *34927890 access forbidden by rule, client: 136.70.247.240, server: fn.binixo.es, request: "GET /.dockerenv HTTP/2.0", host: "auth.pitup.org"
...
show less
Web App Attack
Anonymous
2026-10-09 20:40:04
(5 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-09 19:58:06
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:58:00.720982 2026] [security2:error] [pid 29039:tid 29039] [client 136.70.247.240:53824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wpcoc.org"] [uri "/.htpasswd"] [unique_id "aslHSCDC8r-Q8-jPeilsnwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-10-09 19:48:15
(6 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /asset-manifest.json (HTTP/2.0 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /asset-manifest.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:38:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:38:43.615219 2026] [security2:error] [pid 4927:tid 4927] [client 136.70.247.240:46792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "us-war-crimes-commission.org"] [uri "/.htpasswd"] [unique_id "aslCw5fQLaA0iL_Mv-H7uQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:28:42
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:28:34.811030 2026] [security2:error] [pid 27859:tid 27859] [client 136.70.247.240:42522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rimaine.org"] [uri "/.htpasswd"] [unique_id "askyUipNj9Ib8hLrAJDCnwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 18:22:47
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 17:38:30
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:38:26.830872 2026] [security2:error] [pid 6068:tid 6068] [client 136.70.247.240:48578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mvscouts.org"] [uri "/.htpasswd"] [unique_id "askmkhjsaF01olS_xJAXBAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-09 17:33:53
(8 hours ago)
[Fri Oct 09 19:33:50.961372 2026] [security2:error] [pid 1531312:tid 1531328] [client 136.70.247.240 ...
show more
[Fri Oct 09 19:33:50.961372 2026] [security2:error] [pid 1531312:tid 1531328] [client 136.70.247.240:0] [client 136.70.247.240] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "us.mmn.ca"] [uri "/php-cgi/php-cgi.exe"] [unique_id "asklflomkF0VQPuuGacYsgAAAU4"]
[Fri Oct 09 19:33:51.995994 2026] [security2:error] [pid 1531312:tid 1531327] [client 136.70.247.240:0] [client 136.70.247.240] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 25)"] [ver "OWASP_CRS/4.10.0-dev
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
bazter.pro
2026-10-09 17:24:54
(8 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:19:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:19:14.352274 2026] [security2:error] [pid 18619:tid 18619] [client 136.70.247.240:43606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lo-family.org"] [uri "/.htpasswd"] [unique_id "askiEkP3iqt-5Xb7c0zwyQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-09 17:12:19
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:02:01
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:01:54.905388 2026] [security2:error] [pid 17420:tid 17420] [client 136.70.247.240:43146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimmyshakes.org"] [uri "/appearance/../../.env"] [unique_id "askeAm4zXSPNMfeAGcgBkwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 16:29:10
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.247.240 (240.247.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:29:06.607017 2026] [security2:error] [pid 22703:tid 22717] [client 136.70.247.240:39550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "giere.org"] [uri "/.htpasswd"] [unique_id "askWUvjxnQkC_yh7Mv_tLQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack