🇺🇸
TPI-Abuse
2026-09-08 08:14:15
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:14:08.155118 2026] [security2:error] [pid 4288:tid 4339] [client 136.85.17.216:11750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.icbc-canada.com"] [uri "/@fs/.env.staging"] [unique_id "ap_D0Jz1W0EP-vC0Ow2jGQAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-08 08:01:05
(32 minutes ago)
Bad behaviour
Web Spam
🇧🇪
cmbplf
2026-09-08 07:29:15
(1 hour ago)
4.672 requests with url.path */@fs/*
1.120 requests with url.path *.aws/*
935 requests with url.p ...
show more
4.672 requests with url.path */@fs/*
1.120 requests with url.path *.aws/*
935 requests with url.path *credentials.json
932 requests with url.path *config.json
775 requests with url.path *.config/*
379 requests with url.path */proc/*
344 requests with url.path *.ssh/*
216 requests with url.path */auth.json
123 requests with url.path *.local/share/*
111 requests with url.path *config.php
show less
Brute-Force
Bad Web Bot
🇫🇷
dynamix
2026-09-08 07:29:13
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Stara
2026-09-08 07:17:08
(1 hour ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇩🇪
kkw
2026-09-08 05:57:56
(2 hours ago)
[REDACTED] 136.85.17.216 - - [08/Sep/2026:07:57:56 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 301 911 ...
show more
[REDACTED] 136.85.17.216 - - [08/Sep/2026:07:57:56 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 301 911 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:48:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:48:43.949665 2026] [security2:error] [pid 28738:tid 28738] [client 136.85.17.216:53026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.themotelwest.com"] [uri "/@fs/.env"] [unique_id "ap-hu-O1Y04nTDl6P2n8TgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:30:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:30:37.635952 2026] [security2:error] [pid 13735:tid 13735] [client 136.85.17.216:56908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.battlestem.com"] [uri "/@fs/.env"] [unique_id "ap-dfYIT4lszrUGPQg_6OgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-08 05:13:43
(3 hours ago)
26 attacks on password/key grabbing URLs:
GET /id_dsa HTTP/1.1
Hacking
🇫🇷
Octopuce
2026-09-08 04:57:34
(3 hours ago)
Aggressive web search of vulnerable pages: /.env.local /assets../.env /laravel/.env /api/.env /img.. ...
show more
Aggressive web search of vulnerable pages: /.env.local /assets../.env /laravel/.env /api/.env /img../.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:38:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.17.216 (216.17.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:37:57.045488 2026] [security2:error] [pid 24413:tid 24413] [client 136.85.17.216:33706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fromthehandofgodministry.org"] [uri "/@fs/.env"] [unique_id "ap-RJdMY8GSdAMZ2s91JxQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 03:37:19
(4 hours ago)
136.85.17.216 - - [08/Sep/2026:05:37:18 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1 ...
show more
136.85.17.216 - - [08/Sep/2026:05:37:18 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
136.85.17.216 - - [08/Sep/2026:05:37:18 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot) Chrome/134.0.3379.208 Safari/537.36"
136.85.17.216 - - [08/Sep/2026:05:37:18 +0200] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:143.2) Gecko/20100101 Firefox/143.2; compatible; ChatGPT-User/1.0; +https://openai.com/bot"
136.85.17.216 - - [08/Sep/2026:05:37:18 +0200] "GET /@fs/.env.development?raw?? HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonb
...
show less
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 03:08:11
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇦🇷
gaston875
2026-09-08 02:57:05
(5 hours ago)
136.85.17.216 - - [07/Sep/2026:23:57:04 -0300] "GET /.env.local HTTP/1.1" 403 276 "-" "Mozilla/5.0 A ...
show more
136.85.17.216 - - [07/Sep/2026:23:57:04 -0300] "GET /.env.local HTTP/1.1" 403 276 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
Web App Attack
Hacking
🇬🇧
consul.to
2026-09-08 02:31:22
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack