🇺🇸
TPI-Abuse
2026-09-04 16:30:53
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:30:48.485322 2026] [security2:error] [pid 5390:tid 5390] [client 136.109.138.116:5802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.silvermoonpizza.com"] [uri "/@fs/root/.env"] [unique_id "apryOPh-6Qmr-vteZcId9QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-04 15:26:57
(4 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.109.138.116 (US/United States/116.13 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.109.138.116 (US/United States/116.138.109.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.109.138.116 - - [04/Sep/2026:17:26:53 +0200] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/2.0" 200 4750 "-" "Mozilla/5.0 (compatible; Twitterbot/1.0)" "136.109.138.116" host=archivio.vortici.it
show less
Port Scan
🇮🇩
sockominfo
2026-09-04 15:00:09
(5 hours ago)
Active Response: IP 136.109.138.116 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). R ...
show more
Active Response: IP 136.109.138.116 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇹🇼
ip4.tw
2026-09-04 14:40:02
(5 hours ago)
Malicious web scan
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:19:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:19:36.712432 2026] [security2:error] [pid 2759:tid 2759] [client 136.109.138.116:6816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.richardlyne.com"] [uri "/@fs/root/.env"] [unique_id "aprTeI8d2dlXpZGWgSZB2QAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 13:05:23
(7 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇩🇪
iNetWorker
2026-09-04 11:32:51
(8 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:56:51
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:56:43.473187 2026] [security2:error] [pid 27113:tid 27113] [client 136.109.138.116:63114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rlharmongroup.com"] [uri "/@fs/../.env"] [unique_id "apqj66a8-8JhkmIvq6EhIgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:01:31
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:01:24.504415 2026] [security2:error] [pid 17632:tid 17632] [client 136.109.138.116:31038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.barkdull.org"] [uri "/@fs/.env.staging"] [unique_id "apqW9OsjfjLCr5XCacOILgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:42:33
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:42:27.601873 2026] [security2:error] [pid 23439:tid 23439] [client 136.109.138.116:15410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m.closedfortheseason.com"] [uri "/@fs/.env"] [unique_id "apqSgzDII72AarjWMC7hfwAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
leo1305
2026-09-04 09:15:11
(10 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:32:59
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.109.138.116 (116.138.109.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:32:54.466848 2026] [security2:error] [pid 15783:tid 15783] [client 136.109.138.116:44236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whiteblackbird.com"] [uri "/@fs/app/.env"] [unique_id "apqCNnhoMU5QqXpKB4BJEQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 08:20:12
(11 hours ago)
Bot / seems abusive / Apache connections: 38
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
NXTwoThou
2026-09-04 06:21:40
(13 hours ago)
/@fs/../../.env%3Fraw%3F%3F
Web App Attack
🇩🇪
macrob
2026-09-04 06:15:11
(13 hours ago)
2026/09/04 06:15:09 [error] 339398#339398: *554601593 access forbidden by rule, client: 136.109.138. ...
show more
2026/09/04 06:15:09 [error] 339398#339398: *554601593 access forbidden by rule, client: 136.109.138.116, server: binixo.com.ar, request: "GET /@fs/root/.env?raw?? HTTP/2.0", host: "binixo.com.ar", referrer: "https://www.binixo.com.ar/@fs/root/.env?raw??"
2026/09/04 06:15:09 [error] 339398#339398: *554601595 access forbidden by rule, client: 136.109.138.116, server: binixo.com.ar, request: "GET /@fs/app/.env?raw?? HTTP/2.0", host: "binixo.com.ar", referrer: "https://www.binixo.com.ar/@fs/app/.env?raw??"
2026/09/04 06:15:09 [error] 339396#339396: *554601597 access forbidden by rule, client: 136.109.138.116, server: binixo.com.ar, request: "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/2.0", host: "binixo.com.ar", referrer: "https://www.binixo.com.ar/@fs/root/.aws/credentials.bak?raw??"
...
show less
Web App Attack