🇺🇸
WellSpring
2026-09-08 04:58:04
(17 minutes ago)
env leak on thetimeofthereturn.com/@fs/usr/src/app/.env — WellSpr.ing/NetSentinel civic-AI security ...
show more
env leak on thetimeofthereturn.com/@fs/usr/src/app/.env — WellSpr.ing/NetSentinel civic-AI security layer
show less
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-08 04:54:42
(21 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 136.110.70.124 (JP/Japan/124.70.110.136 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.110.70.124 (JP/Japan/124.70.110.136.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
Charlesiv
2026-09-08 04:00:48
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.docker
Timestamp: 2026-09-08T02:54:23Z
Ray ID: a37aab131c030c15
UA: Mozilla/5.0 (compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
🇳🇱
Savvii
2026-09-08 03:21:05
(1 hour ago)
20 attempts against mh-misbehave-ban on pyrus
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:10:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:10:40.932788 2026] [security2:error] [pid 14493:tid 14493] [client 136.110.70.124:16522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.whaletailpuckerbutt.com"] [uri "/@fs/.env"] [unique_id "ap98sKa33oo90VOOWHmbmwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-08 03:03:50
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-08 02:37:33
(2 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /.env /uploads../.env /.docker/.env /v1/.e ...
show more
Aggressive web search of vulnerable pages: /assets../.env /.env /uploads../.env /.docker/.env /v1/.env ...
show less
Web App Attack
🇺🇸
TAY
2026-09-08 02:36:54
(2 hours ago)
136.110.70.124 - - [08/Sep/2026:10:36:23 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 66825 "-" "Moz ...
show more
136.110.70.124 - - [08/Sep/2026:10:36:23 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 66825 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot"
136.110.70.124 - - [08/Sep/2026:10:36:23 +0800] "GET /@fs/../../.env?raw?? HTTP/1.1" 404 66775 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
136.110.70.124 - - [08/Sep/2026:10:36:46 +0800] "GET /@fs/var/www/html/wp-config.php?raw?? HTTP/1.1" 404 66825 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.1578.174 Safari/537.36; compatible; ClaudeBot/1.0; [email protected] "
136.110.70.124 - - [08/Sep/2026:10:36:46 +0800] "GET /@fs/../../../../../proc/self/environ?raw?? HTTP/1.1" 404 66775 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.6 Safari/605.1.15; compatible; GPTBot/1.2; +https://openai.com/gptbot"
136.110.70.124 - - [08/
...
show less
Brute-Force
🇫🇷
masterguru
2026-09-08 02:31:14
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:31:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:31:05.084691 2026] [security2:error] [pid 5397:tid 5397] [client 136.110.70.124:27926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.quintessence.com.webdub.com"] [uri "/@fs/root/.env"] [unique_id "ap9zaQeERtZVNf7UwYMSkwAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:13:48
(3 hours ago)
(mod_security) mod_security (id:243420) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:243420) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:13:41.345539 2026] [security2:error] [pid 12759:tid 12759] [client 136.110.70.124:60072] ModSecurity: Access denied with code 403 (phase 3). Match of "validateByteRange 0-31" against "ARGS:raw??" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "6640"] [id "243420"] [rev "4"] [msg "COMODO WAF: Information disclosure vulnerability in Eclipse Jetty before 9.2.9.v20150224 (CVE-2015-2080)||www.ottocustoms.g-h2o.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.ottocustoms.g-h2o.com"] [uri "/.env"] [unique_id "ap9vVVo0TnGXC_lt9XefRgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-08 02:08:25
(3 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇫🇷
dynamix
2026-09-08 01:55:09
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:19:02
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.70.124 (124.70.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:18:58.021933 2026] [security2:error] [pid 1026614:tid 1026625] [client 136.110.70.124:47546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wijaya.biz"] [uri "/@fs/app/.env"] [unique_id "ap9iguWNzL2fmfkVZUhuXQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 01:12:35
(4 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack