๐ณ๐ฑ
melroy89
2026-10-10 07:04:09
(8 hours ago)
2026/10/10 09:04:08 [error] 1997009#1997009: *2869747 limiting requests, excess: 5.721 by zone "ip", ...
show more
2026/10/10 09:04:08 [error] 1997009#1997009: *2869747 limiting requests, excess: 5.721 by zone "ip", client: "136.92.13.159", server: "_", request_line: "GET /sw.js HTTP/1.1", host: "app2.libreweb.org"
2026/10/10 09:04:08 [error] 1997009#1997009: *2869747 limiting requests, excess: 5.595 by zone "ip", client: "136.92.13.159", server: "_", request_line: "GET /service-worker.js HTTP/1.1", host: "app2.libreweb.org"
2026/10/10 09:04:09 [error] 1997009#1997009: *2869747 limiting requests, excess: 5.022 by zone "ip", client: "136.92.13.159", server: "_", request_line: "GET /runtime-config.js HTTP/1.1", host: "app2.libreweb.org"
...
show less
Web App Attack
Anonymous
2026-10-10 03:20:05
(12 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-10 02:54:36
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 22:54:28.474699 2026] [security2:error] [pid 9433:tid 9433] [client 136.92.13.159:36234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisk.org"] [uri "/.env.production"] [unique_id "asmo5NlEHODilQevN42d5wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 02:30:08
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 22:30:03.676555 2026] [security2:error] [pid 16458:tid 16458] [client 136.92.13.159:44044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohleap.org"] [uri "/appearance/../../.env"] [unique_id "asmjK5F6J0kfjvRPZ3-YugAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 02:11:23
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 22:11:19.349764 2026] [security2:error] [pid 27764:tid 27764] [client 136.92.13.159:59464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalpozzolanassociation.org"] [uri "/.htpasswd"] [unique_id "asmex7MrfUQ5mtDiIxmODAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 02:09:25
(13 hours ago)
136.92.13.159 - - [10/Oct/2026:04:09:23 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; And ...
show more
136.92.13.159 - - [10/Oct/2026:04:09:23 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.92.13.159 - - [10/Oct/2026:04:09:24 +0200] "GET /auth HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.92.13.159 - - [10/Oct/2026:04:09:24 +0200] "GET /users/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.92.13.159 - - [10/Oct/2026:04:09:24 +0200] "GET /login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
136.92.13.159 - - [10/Oct/2026:04:09:24 +0200] "GET /user/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 01:47:09
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.92.13.159 (159.13.92.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.92.13.159 (159.13.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:47:01.938550 2026] [security2:error] [pid 15608:tid 15608] [client 136.92.13.159:33314] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mvscouts.org|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mvscouts.org"] [uri "/server.key"] [unique_id "asmZFeYn9WXT8mtS6INEKAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 01:19:43
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 21:19:35.703969 2026] [security2:error] [pid 6558:tid 6686] [client 136.92.13.159:35186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "montanatribes.org"] [uri "/static/../../../a/../../../../.env"] [unique_id "asmSp5AD1JRHawxMsaCb3AAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-10-10 01:00:57
(14 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-10-10 00:54:56
(14 hours ago)
Scanning for web/db/file exploits on www.mindatwork.org
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 00:46:30
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.13.159 (159.13.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 20:46:24.849188 2026] [security2:error] [pid 30375:tid 30375] [client 136.92.13.159:37642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michalovic.org"] [uri "/.htpasswd"] [unique_id "asmK4CLUkY3QY27Kx4H2gQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Major Hostility
2026-10-10 00:39:21
(15 hours ago)
"GET /z9x8c7v6b5-debug-trigger-[DOMAIN].org HTTP/1.1" 404
"GET /u96klpwy04xjnpphfq70 HTTP/1.1" 404
" ...
show more
"GET /z9x8c7v6b5-debug-trigger-[DOMAIN].org HTTP/1.1" 404
"GET /u96klpwy04xjnpphfq70 HTTP/1.1" 404
"POST /graphql HTTP/1.1" 404
"GET /signin HTTP/1.1" 404
"POST /api/graphql HTTP/1.1" 404
"GET /assets/manifest.json HTTP/1.1" 404
"POST /v1/graphql HTTP/1.1" 404
"GET /webpack-stats.json HTTP/1.1" 404
"GET /dist/manifest.json HTTP/1.1" 404
"GET /signup HTTP/1.1" 404
"GET /user/login HTTP/1.1" 404
"GET /register HTTP/1.1" 404
"GET /forgot-password HTTP/1.1" 404
"GET /asset-manifest.json HTTP/1.1" 404
"GET /admin HTTP/1.1" 404
"GET /reset-password HTTP/1.1" 404
"GET /admin/login HTTP/1.1" 404
"GET /dashboard HTTP/1.1" 404
"GET /backoffice HTTP/1.1" 404
"GET /manifest.jso
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-10 00:33:06
(15 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
konseptit
2026-10-10 00:29:13
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.92.13.159 (DE/Germany/159.13.92.136 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.92.13.159 (DE/Germany/159.13.92.136.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Alt255
2026-10-10 00:15:37
(15 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.92.13.159 - - [10/Oct/2026:02:15:24 +0200] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/2.0" 301 474 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Bad Web Bot
Web App Attack