🇧🇪
cmbplf
2026-09-12 17:48:44
(11 minutes ago)
244 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-12 16:51:29
(1 hour ago)
Date: 2026/09/13 01 51 29
URI: http://www.adelabelly.com/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:43:02
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:42:56.808725 2026] [security2:error] [pid 12945:tid 12945] [client 136.70.162.27:51836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adults-biz.com"] [uri "/.env.js"] [unique_id "aqVzABBVAaXp0Tngnu15aQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 15:06:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:05:58.561828 2026] [security2:error] [pid 14767:tid 14767] [client 136.70.162.27:38334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.addisonchiropracticcenter.com"] [uri "/.env.local"] [unique_id "aqVqVjovAJytRXpn6NJ2VAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 05:34:25
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 01:34:20.686941 2026] [security2:error] [pid 27931:tid 27931] [client 136.70.162.27:46880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.additiveevoting.com"] [uri "/.env"] [unique_id "aqTkXKlZVRBY3wG9fXH-fgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-12 05:33:35
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
Anonymous
2026-09-12 03:51:08
(14 hours ago)
136.70.162.27 - - [11/Sep/2026:22:51:07 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compat ...
show more
136.70.162.27 - - [11/Sep/2026:22:51:07 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 136.70.162.27
136.70.162.27 - - [11/Sep/2026:22:51:07 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 136.70.162.27
136.70.162.27 - - [11/Sep/2026:22:51:07 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 136.70.162.27
136.70.162.27 - - [11/Sep/2026:22:51:07 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 136.70.162.27
136.70.162.27 - - [11/Sep/2026:22:51:07 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 136.70.162.27
136.70.162.27 - - [11/Sep/2026:22:51:07 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible;
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jmr777
2026-09-11 19:19:00
(22 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile||MV:/.env||RSV:8.59||T:APACHE||
Sensor:
mods ...
show more
IM360 WAF: Direct access to sensitive file or dotfile||MV:/.env||RSV:8.59||T:APACHE||
Sensor:
modsec
Rule:
77045402
Abuser:
136.70.162.27
show less
Web App Attack
🇨🇦
Mediashaker
2026-09-11 18:21:47
(23 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.70.162.27 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 136.70.162.27 (US/United States/27.162.70.136.bc.googleusercontent.com)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 18:18:16
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.162.27 (27.162.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:18:10.413066 2026] [security2:error] [pid 26287:tid 26287] [client 136.70.162.27:53676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adspirowellness.com"] [uri "/@fs/.env"] [unique_id "aqRF4jgZlhp-Xq_aHsAGcwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 18:05:02
(23 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:54:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.70.162.27 (27.162.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.162.27 (27.162.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:54:19.328385 2026] [security2:error] [pid 18420:tid 18420] [client 136.70.162.27:56892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adorningmetal.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adorningmetal.com"] [uri "/rclone.conf"] [unique_id "aqRAS4r_wj0R5iB5O-8FEwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-11 17:44:32
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /admin/.env /config/.env ...
Web App Attack
🇫🇷
masterguru
2026-09-11 17:37:32
(1 day ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 17:33:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 136.70.162.27 (27.162.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 136.70.162.27 (27.162.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:33:46.472356 2026] [security2:error] [pid 3564:tid 3564] [client 136.70.162.27:59416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||adm-sal.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adm-sal.com"] [uri "/rclone.conf"] [unique_id "aqQ7eg6px6sAtw7vTV2-TwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack