🇺🇸
TPI-Abuse
2026-09-09 13:48:16
(30 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:48:08.483730 2026] [security2:error] [pid 1412692:tid 1412713] [client 136.85.117.153:25126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.super-8mm.com"] [uri "/@fs/root/.env"] [unique_id "aqFjmAgKY_ingMP3sXCwgwAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-09 13:26:12
(52 minutes ago)
URL Probing: /@fs/root/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:52:49
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:52:45.941669 2026] [security2:error] [pid 24249:tid 24249] [client 136.85.117.153:38138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kalvannaawards.com"] [uri "/@fs/.env"] [unique_id "aqFWnUCcSoe_K5HMHh28MwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:22:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:22:41.849430 2026] [security2:error] [pid 31130:tid 31130] [client 136.85.117.153:21112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "denvercitymotorparts.com"] [uri "/@fs/app/.env"] [unique_id "aqFPkRHbGl1kdzY3VD8RkwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:54:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:54:27.511943 2026] [security2:error] [pid 5252:tid 5252] [client 136.85.117.153:22360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.petsnality.com"] [uri "/@fs/.env"] [unique_id "aqFI8_T8kLa29S9otZ6mLwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
TheDjRider
2026-09-09 11:35:52
(2 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-09T11:35:50.049015196Z. Context: http_status=500
show less
Web App Attack
Anonymous
2026-09-09 11:07:03
(3 hours ago)
Automated web scanner. Requested suspicious paths: /.env | /@fs/..%252f..%252f..%252f..%252f..%252fr ...
show more
Automated web scanner. Requested suspicious paths: /.env | /@fs/..%252f..%252f..%252f..%252f..%252froot/.env | /@fs/.env.production | /@fs/src/.env | /@fs/etc/passwd | /@fs/root/.env | /@fs/app/.env | /@fs/.env. UTC: 2026-09-09 10:27:17.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 10:14:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:14:46.975719 2026] [security2:error] [pid 12783:tid 12783] [client 136.85.117.153:29346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hollistercomputer.com"] [uri "/@fs/src/.env"] [unique_id "aqExlvrTtgCtpqHm6s_tMwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 09:26:53
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 05:26:47.885431 2026] [security2:error] [pid 27904:tid 27904] [client 136.85.117.153:50778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kooroshvaziri.com"] [uri "/@fs/src/.env"] [unique_id "aqEmV2XqVHYvTSehaawSdwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-09 08:18:39
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-09 07:57:08
(6 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-09 07:45:26
(6 hours ago)
PSCSERV WPSCAN 136.85.117.153
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 07:20:25
(6 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-09 07:08:47
(7 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 06:49:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.117.153 (153.117.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:49:15.692741 2026] [security2:error] [pid 28794:tid 28794] [client 136.85.117.153:38830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stoutmen.com"] [uri "/@fs/../.env"] [unique_id "aqEBa8heffDq_y3mRaQ3TQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack