🇺🇸
TPI-Abuse
2026-09-07 10:30:21
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:30:15.993247 2026] [security2:error] [pid 5749:tid 5749] [client 136.112.228.33:41828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lolycarrillo.com"] [uri "/@fs/.env"] [unique_id "ap6SNyX1ZslwjrvHqIKzgAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
creechy
2026-09-07 10:20:46
(4 hours ago)
136.112.228.33 - - [07/Sep/2026:03:20:36 -0700] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 772 "-" "Mozi ...
show more
136.112.228.33 - - [07/Sep/2026:03:20:36 -0700] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 772 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/148.0.3651.91 Mobile Safari/537.36"
...
show less
Hacking
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 09:39:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:39:39.973332 2026] [security2:error] [pid 1578687:tid 1578687] [client 136.112.228.33:38042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.e-zschedule.com"] [uri "/@fs/src/.env"] [unique_id "ap6GW95eX1uQw8zOaMJUAAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-07 09:06:11
(5 hours ago)
CloudLinux/Plesk alert - host=cloudlinux dominio=business-central.it ip=136.112.228.33 richieste=406 ...
show more
CloudLinux/Plesk alert - host=cloudlinux dominio=business-central.it ip=136.112.228.33 richieste=406 rischio=ALTO score=22 motivi=molte_richieste,molte_uri_uniche,molti_404,ua_script_bot,path_sospetti,api,enumerazione_id cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
🇫🇷
masterguru
2026-09-07 09:00:21
(5 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:57:53
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:57:45.374777 2026] [security2:error] [pid 12592:tid 12592] [client 136.112.228.33:31852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pawzy.app.lucid-events.com"] [uri "/@fs/.env"] [unique_id "ap58icLE45tFDZ4PRFQvPwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 08:34:35
(5 hours ago)
3.088 requests with url.path */@fs/*
323 requests with url.path *.config/*
212 requests with url. ...
show more
3.088 requests with url.path */@fs/*
323 requests with url.path *.config/*
212 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 08:32:14
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:32:08.281425 2026] [security2:error] [pid 17905:tid 17905] [client 136.112.228.33:30340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ajwood.net"] [uri "/@fs/.env.development"] [unique_id "ap52iMpA36jtja76cdTHFgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-07 08:23:27
(6 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 136.112.228.33 (US/United States/33.228.112.136.bc.googleuserc ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 136.112.228.33 (US/United States/33.228.112.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.112.228.33 - - [07/Sep/2026:10:23:26 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 200 12046 "-" "Mozilla/5.0 (compatible; GPTBot/1.2; +https://openai.com/gptbot)" "-" host=www.gestionale.mediaqualitylab.com
show less
Port Scan
Anonymous
2026-09-07 07:56:33
(6 hours ago)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 07:42:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:42:10.691443 2026] [security2:error] [pid 26207:tid 26207] [client 136.112.228.33:1124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jchiggins.nashes.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap5q0o31ekf_ZTrxYRBJqgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-07 07:39:54
(6 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: path_trav ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: path_traversal, env_probe, aws_creds, source_backup, ssh_keys, ai_secrets. Observed by 1 sensor(s); 119 hits.
show less
Web App Attack
🇫🇷
thilo
2026-09-07 07:29:07
(7 hours ago)
Probe for vulnerabilities. Path attempted: /@fs/.env.development
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:10:40
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:10:34.751460 2026] [security2:error] [pid 25177:tid 25177] [client 136.112.228.33:28036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jmms.mx"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap5jatP8zrjW30tOuu7NiAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:51:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.112.228.33 (33.228.112.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:51:07.829259 2026] [security2:error] [pid 7541:tid 7549] [client 136.112.228.33:40044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.belfastpropertyagency.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap5e277hI2b01ETxEMOlWwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack