๐ซ๐ท
masterguru
2026-08-29 00:46:12
(4 minutes ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-29 00:43:39
(7 minutes ago)
(mod_security) mod_security (id:949110) triggered by 136.66.66.192 (US/United States/192.66.66.136.b ...
show more
(mod_security) mod_security (id:949110) triggered by 136.66.66.192 (US/United States/192.66.66.136.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ง๐พ
lns.bz
2026-08-29 00:28:23
(22 minutes ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:25:14
(25 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.66.66.192 (192.66.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.66.192 (192.66.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:25:08.835704 2026] [security2:error] [pid 3363342:tid 3363365] [client 136.66.66.192:16570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.alfred.merart.com"] [uri "/@fs/root/.env"] [unique_id "apIm5G-f09rsyFsPsuSugwAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 00:09:21
(41 minutes ago)
Aggressive web scan
Web App Attack
๐ฎ๐น
VHosting
2026-08-28 23:35:03
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 23:28:13
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 23:10:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.66.66.192 (192.66.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.66.192 (192.66.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:10:30.967932 2026] [security2:error] [pid 13301:tid 13301] [client 136.66.66.192:17200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.michaelgardner.com"] [uri "/@fs/.env"] [unique_id "apIVZjADo-NrmRNHE6kI3gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-28 23:02:21
(1 hour ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, path_traversal, aws_creds, source_backup, ssh_keys, ai_secrets, git_exposure, config_backup. Observed by 1 sensor(s); 631 hits.
show less
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-28 22:44:41
(2 hours ago)
Try to access /@fs/.env?raw??
Web App Attack
๐ณ๐ฑ
SchorelWeb
2026-08-28 22:31:21
(2 hours ago)
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 136.66.66.192, Reason:[(Suspicious02) Suspicio ...
show more
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 136.66.66.192, Reason:[(Suspicious02) Suspicious activity detected 136.66.66.192 (US/United States/192.66.66.136.bc.googleusercontent.com): 10 in the last 3600 secs]
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-28 22:25:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.66.66.192 (192.66.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.66.192 (192.66.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:25:45.362793 2026] [security2:error] [pid 29227:tid 29227] [client 136.66.66.192:25742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.paleopathologist.com"] [uri "/@fs/.env"] [unique_id "apIK6d5fr464d-cGU85ylgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-28 22:25:15
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.66.66.192 (US/United States/192.66.6 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 136.66.66.192 (US/United States/192.66.66.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.66.66.192 - - [29/Aug/2026:00:25:10 +0200] "GET /@fs/home/debian/.aws/credentials?raw?? HTTP/2.0" 404 201 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Twitterbot/1.0)" "136.66.66.192" host=ipv6.lisoladeidesideri.it
show less
Port Scan
๐ซ๐ท
Octopuce
2026-08-28 22:14:04
(2 hours ago)
Aggressive web search of vulnerable pages: /img../.env /frontend/.env /.env /v1/.env /docker/.env . ...
show more
Aggressive web search of vulnerable pages: /img../.env /frontend/.env /.env /v1/.env /docker/.env ...
show less
Web App Attack