Anonymous
2026-10-11 08:26:24
(5 hours ago)
"GET /api/.env HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
creechy
2026-10-11 08:15:07
(6 hours ago)
136.111.0.191 - - [11/Oct/2026:01:14:57 -0700] "GET /media../.env HTTP/1.1" 404 768 "-" "Mozilla/5.0 ...
show more
136.111.0.191 - - [11/Oct/2026:01:14:57 -0700] "GET /media../.env HTTP/1.1" 404 768 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Hacking
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-11 05:40:35
(8 hours ago)
[ti-24al] Web exploit scanning: 6 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 6 suspicious requests detected by fail2ban jail apache-scanner. Example: 136.111.0.191 - - [11/Oct/2026:07:40:16 +0200] "GET //.env HTTP/2.0" 403 547 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
136.111.0.191 - - [11/Oct/2026:07:40:16 +0200] "GET /.ssh/config HTTP/2.0" 404 2004 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
136.111.0.191 - - [11/Oct/2026:07:40:16 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
136.111.0.191 - - [11/Oct/2026:07:40:16 +0200] "GET /files../.env HTTP/2.0" 404 2004 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
136.111.0.191 - - [11/Oct/2026:07:40:16 +0200]
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-11 05:03:15
(9 hours ago)
2026/10/11 06:03:12 [error] 4060693#4060693: *2062768 access forbidden by rule, client: 136.111.0.19 ...
show more
2026/10/11 06:03:12 [error] 4060693#4060693: *2062768 access forbidden by rule, client: 136.111.0.191, server: vp-arc.org, request: "GET /_nuxt/../.env HTTP/2.0", host: "vp-arc.org"
2026/10/11 06:03:12 [error] 4060693#4060693: *2062768 access forbidden by rule, client: 136.111.0.191, server: vp-arc.org, request: "GET /api/orders/..%2f..%2f.env HTTP/2.0", host: "vp-arc.org"
2026/10/11 06:03:12 [error] 4060693#4060693: *2062768 access forbidden by rule, client: 136.111.0.191, server: vp-arc.org, request: "GET /api/data/..%2f..%2f.env HTTP/2.0", host: "vp-arc.org"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Teufel100
2026-10-11 04:50:48
(9 hours ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 04:45:50
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 00:45:46.103781 2026] [security2:error] [pid 23919:tid 23919] [client 136.111.0.191:54002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "progressivefileshare.org"] [uri "/@fs/app/.env"] [unique_id "assUevuVSakbrf9vnxyVUQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-11 04:36:28
(9 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ธ๐ฌ
naveeddaros
2026-10-11 04:28:35
(9 hours ago)
HTTP Flood DDoS attack detected
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-11 04:21:16
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 11 00:21:13.952966 2026] [security2:error] [pid 18790:tid 18790] [client 136.111.0.191:37452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glassicannex.org"] [uri "/userfiles"] [unique_id "assOuVrjaScdCkB4SRGy2wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-11 04:20:39
(9 hours ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-10-11 04:07:40
(10 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
WellSpring
2026-10-11 03:55:55
(10 hours ago)
env leak on freeproduce.org/api%2F.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 03:24:35
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 23:24:30.144241 2026] [security2:error] [pid 30290:tid 30290] [client 136.111.0.191:42568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flinthillsveterans.org"] [uri "/.//.env"] [unique_id "assBbqqFXef47Azb5HlD9QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 02:35:04
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.0.191 (191.0.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 22:34:59.570607 2026] [security2:error] [pid 19755:tid 19755] [client 136.111.0.191:36104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exhaustthelimits.org"] [uri "/api/.env/public/.env"] [unique_id "asr102zXnt8XgFRSW22ocgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-11 02:33:24
(11 hours ago)
6.441 requests with url.path *.env
446 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot