🇬🇧
consul.to
2026-09-09 22:27:35
(32 minutes ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
javierin
2026-09-09 21:49:03
(1 hour ago)
136.70.126.85 - regalo-estrenar-casa.es - - [09/Sep/2026:21:49:03 +0000] "GET /@fs/..%252f..%252f..% ...
show more
136.70.126.85 - regalo-estrenar-casa.es - - [09/Sep/2026:21:49:03 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 117 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
136.70.126.85 - regalo-estrenar-casa.es - - [09/Sep/2026:21:49:03 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.6151.94 Mobile Safari/537.36; compatible; Slackbot-LinkExpanding/1.0; +https://api.slack.com/robots"
...
show less
Web App Attack
Hacking
🇨🇿
akac
2026-09-09 20:01:27
(2 hours ago)
Web vulnerability scanning: HTTP/1.1 GET /@fs/.env?raw??
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-09 18:57:42
(4 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-09 17:37:22
(5 hours ago)
URL Probing: /@fs/.env
Web App Attack
🇸🇪
SkyDancer
2026-09-09 16:18:09
(6 hours ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
Anonymous
2026-09-09 15:40:45
(7 hours ago)
Malicious activity detected
DDoS Attack
Bad Web Bot
Web App Attack
🇺🇸
Penny Packer
2026-09-09 15:14:00
(7 hours ago)
Fail2Ban apache-404
Web App Attack
🇩🇪
Vegascosmetics
2026-09-09 12:21:41
(10 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (61, Abuse: 52)
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:06:31
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.126.85 (85.126.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.126.85 (85.126.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:06:23.002962 2026] [security2:error] [pid 26301:tid 26301] [client 136.70.126.85:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rareearth.technology"] [uri "/@fs/../.env"] [unique_id "aqFLv96zd-1SEyCrluPTsQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:51:17
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.126.85 (85.126.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.126.85 (85.126.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:51:08.929787 2026] [security2:error] [pid 30337:tid 30337] [client 136.70.126.85:54318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.odinathletes.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "aqFILOc_jfnyYBryom2_ZQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 11:03:12
(11 hours ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 10:24:37
(12 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇸🇰
Shadow77
2026-09-09 09:50:00
(13 hours ago)
136.70.126.85 - - [09/Sep/2026:05:23:29 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 671 "-" "Moz ...
show more
136.70.126.85 - - [09/Sep/2026:05:23:29 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 671 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user) Chrome/109.0.3610.247 Mobile Safari/537.36"
136.70.126.85 - - [09/Sep/2026:05:23:29 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 671 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot) Chrome/128.0.2772.211 Safari/537.36"
136.70.126.85 - - [09/Sep/2026:05:23:29 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 403 674 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_0) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot) Version/19.6 Safari/605.1.15"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:47:33
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.126.85 (85.126.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.126.85 (85.126.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:47:27.033566 2026] [security2:error] [pid 9056:tid 9056] [client 136.70.126.85:5344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radixtx.com"] [uri "/@fs/src/.env"] [unique_id "aqErL60qh6FHzwuLdfpZgAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack