๐ฉ๐ช
Gwyneth Llewelyn
2026-09-24 11:49:23
(3 hours ago)
2026/09/24 12:49:21 [error] 325888#325888: *1829285 limiting requests, excess: 200.530 by zone "floo ...
show more
2026/09/24 12:49:21 [error] 325888#325888: *1829285 limiting requests, excess: 200.530 by zone "flood", client: 136.107.187.28, server: files.betatechnologies.info, request: "GET /api/.env.bak HTTP/2.0", host: "files.betatechnologies.info"
2026/09/24 12:49:21 [error] 325888#325888: *1829278 limiting requests, excess: 200.290 by zone "flood", client: 136.107.187.28, server: files.betatechnologies.info, request: "GET /debug/pprof/cmdline HTTP/2.0", host: "files.betatechnologies.info"
2026/09/24 12:49:21 [error] 325888#325888: *1829278 limiting requests, excess: 200.580 by zone "flood", client: 136.107.187.28, server: files.betatechnologies.info, request: "GET /ai/.env HTTP/2.0", host: "files.betatechnologies.info"
show less
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-23 22:33:57
(16 hours ago)
2026/09/23 23:33:55 [error] 325888#325888: *1688605 access forbidden by rule, client: 136.107.187.28 ...
show more
2026/09/23 23:33:55 [error] 325888#325888: *1688605 access forbidden by rule, client: 136.107.187.28, server: [redacted], request: "GET /media../.env HTTP/2.0", host: "web.betatechnologies.info"
2026/09/23 23:33:55 [error] 325888#325888: *1688605 access forbidden by rule, client: 136.107.187.28, server: [redacted], request: "GET /static//.env HTTP/2.0", host: "web.betatechnologies.info"
2026/09/23 23:33:56 [error] 325888#325888: *1688605 access forbidden by rule, client: 136.107.187.28, server: [redacted], request: "GET /.//.env HTTP/2.0", host: "web.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-23 22:31:58
(16 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-23 22:29:02
(16 hours ago)
2026-09-24 00:27:23 GET /sa.json [301] && 2026-09-24 00:27:23 GET /firebase-credentials.json [301] & ...
show more
2026-09-24 00:27:23 GET /sa.json [301] && 2026-09-24 00:27:23 GET /firebase-credentials.json [301] && 2026-09-24 00:27:23 GET /gcp-key.json [301] && 207 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:14:20
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.187.28 (28.187.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.187.28 (28.187.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:14:13.581451 2026] [security2:error] [pid 12274:tid 12274] [client 136.107.187.28:46322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vfflag.info"] [uri "/.env"] [unique_id "arRPNY2U2VtFlMHsidz0VwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
enpepet
2026-09-23 22:01:59
(17 hours ago)
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) ...
show more
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/) URL:/.env?raw
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-23 21:58:52
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.187.28 (28.187.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.187.28 (28.187.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:58:45.999662 2026] [security2:error] [pid 8384:tid 8384] [client 136.107.187.28:45954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oss-in-atm.info"] [uri "/api/.env"] [unique_id "arRLlSNO3xG0GH3coia69QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 21:51:17
(17 hours ago)
[Wed Sep 23 23:51:12.282684 2026] [access_compat:error] [pid 3664671:tid 3664671] [client 136.107.18 ...
show more
[Wed Sep 23 23:51:12.282684 2026] [access_compat:error] [pid 3664671:tid 3664671] [client 136.107.187.28:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/rclone.conf
[Wed Sep 23 23:51:12.800569 2026] [access_compat:error] [pid 3665062:tid 3665062] [client 136.107.187.28:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.aws
[Wed Sep 23 23:51:12.803506 2026] [access_compat:error] [pid 3661684:tid 3661684] [client 136.107.187.28:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.aws
[Wed Sep 23 23:51:15.559565 2026] [access_compat:error] [pid 3661685:tid 3661685] [client 136.107.187.28:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/server.key
[Wed Sep 23 23:51:15.572379 2026] [access_compat:error] [pid 3665062:tid 3665062] [client 136.107.187.28:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.s
...
show less
Web Spam
Web App Attack
๐ฌ๐ง
Apache
2026-09-23 21:26:50
(17 hours ago)
(mod_security) mod_security (id:930130) triggered by 136.107.187.28 (US/United States/28.187.107.136 ...
show more
(mod_security) mod_security (id:930130) triggered by 136.107.187.28 (US/United States/28.187.107.136.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
itsolon
2026-09-23 21:20:22
(17 hours ago)
[23/Sep/2026:23:20:22 +0200] 179019842271.407817 136.107.187.28 0 217.154.7.177 443
[23/Sep/2026:23: ...
show more
[23/Sep/2026:23:20:22 +0200] 179019842271.407817 136.107.187.28 0 217.154.7.177 443
[23/Sep/2026:23:20:22 +0200] 179019842221.426589 136.107.187.28 0 217.154.7.177 443
[23/Sep/2026:23:20:22 +0200] 179019842258.301852 136.107.187.28 0 217.154.7.177 443
[23/Sep/2026:23:20:22 +0200] 179019842246.255882 136.107.187.28 0 217.154.7.177 443
[23/Sep/2026:23:20:22 +0200] 179019842257.128273 136.107.187.28 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐จ๐ญ
zynex
2026-09-23 19:50:00
(19 hours ago)
URL Probing: /static/.env
Web App Attack
๐น๐ผ
tyebstx
2026-09-23 19:48:25
(19 hours ago)
Wazuh Alert Evidence: 136.107.187.28 - - [23/Sep/2026:19:48:22 +0000] "GET / HTTP/2.0" 444 0 "-" "Mo ...
show more
Wazuh Alert Evidence: 136.107.187.28 - - [23/Sep/2026:19:48:22 +0000] "GET / HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "-"
show less
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-23 18:52:42
(20 hours ago)
2026/09/23 19:52:40 [error] 325888#325888: *1651507 access forbidden by rule, client: 136.107.187.28 ...
show more
2026/09/23 19:52:40 [error] 325888#325888: *1651507 access forbidden by rule, client: 136.107.187.28, server: betatechnologies.info, request: "GET /api/.env HTTP/2.0", host: "betatechnologies.info"
2026/09/23 19:52:40 [error] 325888#325888: *1651538 access forbidden by rule, client: 136.107.187.28, server: betatechnologies.info, request: "GET /backend/.env HTTP/2.0", host: "betatechnologies.info"
2026/09/23 19:52:40 [error] 325888#325888: *1651507 access forbidden by rule, client: 136.107.187.28, server: betatechnologies.info, request: "GET /admin/.env HTTP/2.0", host: "betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 18:35:09
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking