🇳🇱
middelkoopcc
2026-09-09 23:41:05
(54 minutes ago)
2026-09-10 01:39:15 GET /@fs/app/.env?raw?? [404] && 2026-09-10 01:39:15 GET /@fs/.env.local?raw?? [ ...
show more
2026-09-10 01:39:15 GET /@fs/app/.env?raw?? [404] && 2026-09-10 01:39:15 GET /@fs/.env.local?raw?? [404] && 2026-09-10 01:39:15 GET /@fs/etc/passwd?raw?? [404] && 109 more within 20 minutes
show less
Web App Attack
🇷🇴
iulianh
2026-09-09 23:19:32
(1 hour ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-09 21:23:01
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 17:22:57.095466 2026] [security2:error] [pid 729:tid 729] [client 136.110.75.14:43538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.alexsource.com"] [uri "/@fs/../.env"] [unique_id "aqHOMXTob4Z9OGS1SR_y3wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 19:09:33
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:09:28.775638 2026] [security2:error] [pid 17298:tid 17298] [client 136.110.75.14:37636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dualspiralsystems.com"] [uri "/@fs/../.env"] [unique_id "aqGu6E1Aru_fpmgOYFhFFwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 18:47:35
(5 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/root/.env (+12 more) | 2026-09-09 18:47 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 18:45:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 14:45:28.209570 2026] [security2:error] [pid 15205:tid 15205] [client 136.110.75.14:10138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.riedmannfamily.com"] [uri "/@fs/../../.env"] [unique_id "aqGpSATPeYbNW3QuptJHeQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Lentini
2026-09-09 17:46:16
(6 hours ago)
visuitslagen.nl: malicious request:/@fs/src/.env
Web App Attack
🇵🇱
sigurg
2026-09-09 16:37:35
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇦🇺
electronico
2026-09-09 15:57:44
(8 hours ago)
136.110.75.14 - - [10/Sep/2026:02:57:43 +1100] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env ...
show more
136.110.75.14 - - [10/Sep/2026:02:57:43 +1100] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
136.110.75.14 - - [10/Sep/2026:02:57:43 +1100] "GET /@fs/.env?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
136.110.75.14 - - [10/Sep/2026:02:57:43 +1100] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.3232.232 Safari/537.36; compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots"
136.110.75.14 - - [10/Sep/2026:02:57:43 +1100] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
136.110.75.14 - - [10/Sep/2026:02:57:43 +1100] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 806 "-" "Mozilla/5
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:41:16
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:41:11.561298 2026] [security2:error] [pid 27599:tid 27599] [client 136.110.75.14:56180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.conveyorizedovens.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqF-F6FJiwaaXSzdJiRYiQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-09 14:27:11
(10 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇸🇪
vaia.cloud
2026-09-09 14:05:02
(10 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇳🇴
Bots.go.to.hell
2026-09-09 13:51:45
(10 hours ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
🇳🇱
ConsulHosting
2026-09-09 13:45:59
(10 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:38:26
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.75.14 (14.75.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:38:22.371254 2026] [security2:error] [pid 8585:tid 8585] [client 136.110.75.14:59088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.funkerecords.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqFhTk78zWQvcQ4zhIm2BgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack