๐ณ๐ฑ
Alt255
2026-09-14 10:30:26
(1 day ago)
[ti-14al] Excessive 404 errors (web scanning): 29 suspicious requests detected by fail2ban jail <nam ...
show more
[ti-14al] Excessive 404 errors (web scanning): 29 suspicious requests detected by fail2ban jail <name>. Example: 136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/root/.env\?raw\?\? HTTP/1.1" 404 728 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; PerplexityBot/1.0\; +https://perplexity.ai/perplexitybot\)"
136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/src/.env\?raw\?\? HTTP/1.1" 404 728 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Perplexity-User/1.0\; +https://perplexity.ai/perplexity-user\)"
136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/app/.env\?raw\?\? HTTP/1.1" 404 728 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 14_5\) AppleWebKit/605.1.15 \(KHTML, like Gecko\; compatible\; TelegramBot/1.0\) Version/17.1 Safari/605.1.15"
136.66.33.11 - - \[08/Sep/
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-11 15:34:24
(4 days ago)
136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/root/.env\?raw\?\? HTTP/1.1" 404 728 "-" " ...
show more
136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/root/.env\?raw\?\? HTTP/1.1" 404 728 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; PerplexityBot/1.0\; +https://perplexity.ai/perplexitybot\)"
136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/src/.env\?raw\?\? HTTP/1.1" 404 728 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; Perplexity-User/1.0\; +https://perplexity.ai/perplexity-user\)"
136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/app/.env\?raw\?\? HTTP/1.1" 404 728 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 14_5\) AppleWebKit/605.1.15 \(KHTML, like Gecko\; compatible\; TelegramBot/1.0\) Version/17.1 Safari/605.1.15"
136.66.33.11 - - \[08/Sep/2026:07:11:21 +0200\] "GET /@fs/proc/self/environ\?raw\?\? HTTP/1.1" 404 728 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 14_5\) AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; ClaudeBot/1.0\;
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-11 12:15:04
(4 days ago)
136.66.33.11 - - \[08/Sep/2026:05:51:27 +0200\] "GET /@fs/app/.env\?raw\?\? HTTP/1.1" 301 1202 "-" " ...
show more
136.66.33.11 - - \[08/Sep/2026:05:51:27 +0200\] "GET /@fs/app/.env\?raw\?\? HTTP/1.1" 301 1202 "-" "Mozilla/5.0 \(iPhone\; CPU iPhone OS 18_4 like Mac OS X\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/118.0.7562.201 Mobile Safari/537.36\; compatible\; Twitterbot/1.0"
136.66.33.11 - - \[08/Sep/2026:05:51:27 +0200\] "GET /@fs/.env.production\?raw\?\? HTTP/1.1" 301 1216 "-" "Mozilla/5.0 \(compatible\; Perplexity-User/1.0\; +https://perplexity.ai/perplexity-user\)"
136.66.33.11 - - \[08/Sep/2026:05:51:27 +0200\] "GET /@fs/root/.env\?raw\?\? HTTP/1.1" 301 1204 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\)\; compatible\; Slackbot-LinkExpanding/1.0\; +https://api.slack.com/robots"
136.66.33.11 - - \[08/Sep/2026:05:51:27 +0200\] "GET /@fs/src/.env\?raw\?\? HTTP/1.1" 301 1202 "-" "Mozilla/5.0 \(iPhone\; CPU iPhone OS 16_4 like Mac OS X\) AppleWebKit/605.1.15 \(KHTML, like Gecko\; compatible\; fa
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-09-09 18:45:36
(6 days ago)
Honeypot caught: /.env.production via bot.saec.me. UA: Mozilla/5.0 (compatible; Google-Extended/1.0; ...
show more
Honeypot caught: /.env.production via bot.saec.me. UA: Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html).
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
IoT Targeted
๐ฎ๐ณ
evicky2002
2026-09-09 00:01:20
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 22:02:22
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
๐ซ๐ท
Feelautom
2026-09-08 11:39:36
(1 week ago)
[FeelAutom Auto-Ban] BotIdentityRotation: /@fs/proc/self/environ?raw?? (Score: 200)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-08 11:37:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:37:48.350736 2026] [security2:error] [pid 4190:tid 4264] [client 136.66.33.11:14866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.chadcentral.com"] [uri "/@fs/src/.env"] [unique_id "ap_zjOmTK23ngK0qlxNwrQAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 11:20:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:19:54.282327 2026] [security2:error] [pid 7424:tid 7424] [client 136.66.33.11:14126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.blackstarmgmt.com"] [uri "/@fs/app/.env"] [unique_id "ap_vWuZBTHrrCAy7PihRdwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 11:02:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:01:54.147153 2026] [security2:error] [pid 30451:tid 30451] [client 136.66.33.11:40438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.mcgmcg.com"] [uri "/@fs/.env"] [unique_id "ap_rInPvnnFuO3OXlslrBAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-08 11:00:32
(1 week ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-08 10:26:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:26:31.950402 2026] [security2:error] [pid 6188:tid 6188] [client 136.66.33.11:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.infinitewashing.com"] [uri "/@fs/.env"] [unique_id "ap_i13IIFscv-arPoH-d1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 10:11:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.33.11 (11.33.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:10:57.482959 2026] [security2:error] [pid 29842:tid 29842] [client 136.66.33.11:18440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogerg.com"] [uri "/@fs/root/.env"] [unique_id "ap_fMVWltavY6b_8Ngo4egAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-08 10:05:28
(1 week ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
Anonymous
2026-09-08 09:53:33
(1 week ago)
Multiple web server 400 error codes from same source ip
Web App Attack