๐ฎ๐ณ
walkintoadmin
2026-09-16 14:02:53
(5 days ago)
GCP fleet: Vite /@fs/ path-traversal + cloud-credential harvester, spoofed bot UA; 295 reqs/1d, scan ...
show more
GCP fleet: Vite /@fs/ path-traversal + cloud-credential harvester, spoofed bot UA; 295 reqs/1d, scanner-path ratio 0.76, 0 real-user 200s
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-08 20:13:38
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sweetpuddingtrap.top | URI: /@fs/.env?raw?? | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.3577.147 Safari/537.36; compatible; Twitterbot/1.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 20:11:43
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:11:34.983495 2026] [security2:error] [pid 13863:tid 13863] [client 136.110.58.176:48798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hersbach.net"] [uri "/@fs/.env"] [unique_id "aqBr9nVaG5RNYJzk0jhDkwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-08 20:03:35
(1 week ago)
Suspicious URL access.
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-08 19:58:24
(1 week ago)
(y3) Failed access -byebye- from 136.110.58.176 (SG/Singapore/176.58.110.136.bc.googleusercontent.co ...
show more
(y3) Failed access -byebye- from 136.110.58.176 (SG/Singapore/176.58.110.136.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-08 19:45:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:45:31.812243 2026] [security2:error] [pid 10364:tid 10364] [client 136.110.58.176:35724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dunbartonucc.org"] [uri "/@fs/root/.env"] [unique_id "aqBl245czG0HoAmtzOCauQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-08 19:37:41
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-08 19:24:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:24:41.099415 2026] [security2:error] [pid 4114617:tid 4114617] [client 136.110.58.176:17194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jhonbens.com"] [uri "/@fs/.env"] [unique_id "aqBg-cX8THsuZdqem9fKKAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-08 19:18:48
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 19:09:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:09:01.850329 2026] [security2:error] [pid 5437:tid 5437] [client 136.110.58.176:65386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sublimationconsultants.ipostsocialmedia.com"] [uri "/@fs/.env"] [unique_id "aqBdTZ0_kU2HuZVZzj8jhgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-08 18:40:26
(1 week ago)
225 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-08 18:16:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:15:57.813135 2026] [security2:error] [pid 8312:tid 8312] [client 136.110.58.176:26114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.woodburymeadows.org"] [uri "/@fs/.env"] [unique_id "aqBQ3co2r07-t_XuMLB6LAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
benou2
2026-09-08 18:00:07
(1 week ago)
crowdsecurity/http-sensitive-files
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-08 17:53:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.58.176 (176.58.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:53:54.351979 2026] [security2:error] [pid 10992:tid 11012] [client 136.110.58.176:37942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedprojectmanager.net.aafm.us"] [uri "/@fs/app/.env"] [unique_id "aqBLsg-CJ3pKPw0fWMZIJgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-08 17:31:26
(1 week ago)
136.110.58.176 - - [08/Sep/2026:17:31:06 +0000] "GET /mail/.env HTTP/1.1" 404 210 "-" "Mozilla/5.0 ( ...
show more
136.110.58.176 - - [08/Sep/2026:17:31:06 +0000] "GET /mail/.env HTTP/1.1" 404 210 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.4840.44 Mobile Safari/537.36; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot" "-" edge="136.110.58.176"
136.110.58.176 - - [08/Sep/2026:17:31:16 +0000] "GET /cgi-bin/test?cmd=%3B+echo+GSCAN_CMDI+%23 HTTP/1.1" 404 210 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0) Chrome/134.0.2147.209 Safari/537.36" "-" edge="136.110.58.176"
136.110.58.176 - - [08/Sep/2026:17:31:16 +0000] "GET /cgi-bin/test?cmd=%60echo+GSCAN_CMDI%60 HTTP/1.1" 404 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)" "-" edge="136.110.58.176"
136.110.58.176 - - [08/Sep/2026:17:31:23 +0000] "GET /cgi-bin/fetch?url=http%3A%2F%2F169.254.169.254%2Flatest%2Fmeta-data%2Fiam%2Fsecurity-credentials%2F HTTP/1.1"
...
show less
Bad Web Bot