🇺🇸
WellSpring
2026-09-09 21:20:03
(5 minutes ago)
env leak on 253.today/@fs/home/ubuntu/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 20:38:45
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:38:39.069408 2026] [security2:error] [pid 15581:tid 15581] [client 136.110.69.22:4298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.delidalga.com"] [uri "/@fs/app/.env"] [unique_id "aqHDz3VH_OgLIKelLlssMQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-09 20:25:17
(1 hour ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 20:10:02
(1 hour ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-09 19:51:20
(1 hour ago)
T: f2b 404 5x
Web App Attack
Anonymous
2026-09-09 16:26:58
(4 hours ago)
XSS Attempt
Hacking
🇨🇦
Blinker73
2026-09-09 15:16:37
(6 hours ago)
136.110.69.22 - - [09/Sep/2026:11:16:37 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 301 162 "-" "Mozil ...
show more
136.110.69.22 - - [09/Sep/2026:11:16:37 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot) Chrome/126.0.435.69 Mobile Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:03:50
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:03:43.970414 2026] [security2:error] [pid 21025:tid 21025] [client 136.110.69.22:55374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.numbulary.com"] [uri "/@fs/.env"] [unique_id "aqF1T4v3bjRGBmMaP5t2yQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 14:48:56
(6 hours ago)
cloudlinux2 fail2ban: 2026-09-09 16:43:52,261 fail2ban.filter [1892]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-09 16:43:52,261 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 45.130.83.237 - 2026-09-09 16:43:51cloudlinux2 fail2ban: 2026-09-09 16:43:52,372 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 45.130.83.230 - 2026-09-09 16:43:51cloudlinux2 fail2ban: 2026-09-09 16:43:57,085 fail2ban.filter [1892]: INFO [plesk-apache] Found 193.37.32.140 - 2026-09-09 16:43:57cloudlinux2 fail2ban: 2026-09-09 16:44:31,026 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 136.110.69.22 - 2026-09-09 16:44:30cloudlinux2 fail2ban: 2026-09-09 16:44:31,008 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 136.110.69.22 - 2026-09-09 16:44:30cloudlinux2 fail2ban: 2026-09-09 16:44:30,966 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 136.110.69.22 - 2026-09-09 16:44:30cloudlinux2 fail2ban: 2026-09-09 16:44:30,987 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 136.110.69.22 - 2026-09-09 16:44:30clou
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:36:37
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:36:30.645354 2026] [security2:error] [pid 31215:tid 31215] [client 136.110.69.22:30814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blackjobsnetwork.com"] [uri "/@fs/root/.env"] [unique_id "aqFu7uuI8CJ-pYuNeoYF4gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:06:40
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.69.22 (22.69.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:06:35.584954 2026] [security2:error] [pid 1369:tid 1369] [client 136.110.69.22:40482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portfolioboosterllc.myhomeflyer.com"] [uri "/@fs/root/.env"] [unique_id "aqFn62SLLwcy4D62yPMZxAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 13:36:12
(7 hours ago)
Bot / seems abusive / Apache connections: 31
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 13:33:16
(7 hours ago)
136.110.69.22 - - [09/Sep/2026:15:32:35 +0200] "GET HTTP/1.1" 403 734 "-" "Mozilla/5.0 (compatible; ...
show more
136.110.69.22 - - [09/Sep/2026:15:32:35 +0200] "GET HTTP/1.1" 403 734 "-" "Mozilla/5.0 (compatible; Bytespider; +https://zhanzhang.toutiao.com/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇨🇭
4server
2026-09-09 13:17:35
(8 hours ago)
[WedSep0915:17:29.9762002026][security2:error][pid2219273:tid2219573][client136.110.69.22:0]ModSecur ...
show more
[WedSep0915:17:29.9762002026][security2:error][pid2219273:tid2219573][client136.110.69.22:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:15\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"cadvending.ch\"][uri\"/@fs/../../../../../proc/self/environ\"][unique_id\"aqFcaRN5244B_6AIoAo8aAAAANE\"]
show less
Hacking
Web App Attack
🇩🇪
big-cloud.nl
2026-09-09 12:10:49
(9 hours ago)
Try to access /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??
Web App Attack