๐ง๐ช
cmbplf
2026-10-07 05:40:29
(11 hours ago)
202 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-10-07 04:35:56
(13 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
arsonist
2026-10-06 20:07:26
(21 hours ago)
[fail2ban]
2026-10-06T20:07:24.957774+00:00 arson caddy[1712]: {"level":"info","ts":1791317244.95775 ...
show more
[fail2ban]
2026-10-06T20:07:24.957774+00:00 arson caddy[1712]: {"level":"info","ts":1791317244.957758,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"136.85.20.152","remote_port":"42492","client_ip":"136.85.20.152","proto":"HTTP/2.0","method":"GET","host":"panel.furtress.tf","uri":"/api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env","headers":{"User-Agent":["Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"],"Accept":["*/*"],"Cookie":["REDACTED"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"panel.furtress.tf","ech":false}},"bytes_read":0,"user_id":"","duration":0.00
...
show less
Bad Web Bot
๐ซ๐ท
arsonist
2026-10-06 11:10:01
(1 day ago)
[fail2ban]
2026-10-06T11:10:01.053365+00:00 arson caddy[1712]: {"level":"info","ts":1791285001.05334 ...
show more
[fail2ban]
2026-10-06T11:10:01.053365+00:00 arson caddy[1712]: {"level":"info","ts":1791285001.0533412,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"136.85.20.152","remote_port":"60452","client_ip":"136.85.20.152","proto":"HTTP/2.0","method":"GET","host":"bot.furtress.tf","uri":"/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??","headers":{"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"],"Accept":["*/*"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"bot.furtress.tf","ech":false}},"bytes_read":0,"user_id":"","duration":0.000063339,"size":7,"status":418,"r
...
show less
Bad Web Bot
๐ง๐ฌ
Stoyko Stoykov
2026-10-06 09:24:36
(1 day ago)
136.85.20.152 - - [06/Oct/2026:12:24:36 +0300] "GET /.env.js HTTP/2.0" 404 0 "-" "Mozilla/5.0 AppleW ...
show more
136.85.20.152 - - [06/Oct/2026:12:24:36 +0300] "GET /.env.js HTTP/2.0" 404 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Hacking
Web App Attack
๐ฐ๐ท
ZEROVOX
2026-10-06 08:52:03
(1 day ago)
CrowdSec: crowdsecurity/http-probing detected
Web App Attack
๐ซ๐ท
arsonist
2026-10-06 08:34:50
(1 day ago)
[fail2ban]
2026-10-06T08:34:49.351916+00:00 arson caddy[1712]: {"level":"info","ts":1791275689.35184 ...
show more
[fail2ban]
2026-10-06T08:34:49.351916+00:00 arson caddy[1712]: {"level":"info","ts":1791275689.3518407,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"136.85.20.152","remote_port":"44276","client_ip":"136.85.20.152","proto":"HTTP/2.0","method":"GET","host":"possum.city","uri":"/@fs/src/.env?raw??","headers":{"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["CCBot/2.0 (https://commoncrawl.org/faq/)"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"possum.city","ech":false}},"bytes_read":0,"user_id":"","duration":0.000094708,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=259
...
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-10-06 07:49:18
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
Scampi_ml
2026-10-06 07:26:32
(1 day ago)
31 x HTTP 403/404 responses within 60 seconds. Likely vulnerability scanner or brute-force attack on ...
show more
31 x HTTP 403/404 responses within 60 seconds. Likely vulnerability scanner or brute-force attack on web application paths.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:03:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.85.20.152 (152.20.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.20.152 (152.20.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:02:59.795499 2026] [security2:error] [pid 19493:tid 19493] [client 136.85.20.152:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.click"] [uri "/.env.production"] [unique_id "asSdI6agB_M74Shw5zDXlwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Peter-Johann Sarbach
2026-10-01 23:32:58
(5 days ago)
Hacking website
Hacking
Anonymous
2026-10-01 17:42:11
(5 days ago)
[Thu Oct 01 19:42:10.901395 2026] [php:error] [pid 3830183] [client 136.85.20.152:50514] script '/va ...
show more
[Thu Oct 01 19:42:10.901395 2026] [php:error] [pid 3830183] [client 136.85.20.152:50514] script '/var/www/11spielerinnen.de/public_html/document.php' not found or unable to stat
...
show less
Bad Web Bot
Anonymous
2026-10-01 17:14:20
(6 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:57:15
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.20.152 (152.20.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.20.152 (152.20.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:57:08.137414 2026] [security2:error] [pid 17463:tid 17463] [client 136.85.20.152:36804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.stradcompetition.org"] [uri "/static../.env"] [unique_id "ar6Q5FZ2wotd1iXKKCA_jgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chronos
2026-10-01 16:14:51
(6 days ago)
[AUTORAVALT][[01/10/2026 - 13:14:51 -03:00 UTC]
Attack from [Google LLC]
[136.85.20.152][152.20.85.1 ...
show more
[AUTORAVALT][[01/10/2026 - 13:14:51 -03:00 UTC]
Attack from [Google LLC]
[136.85.20.152][152.20.85.136.bc.googleusercontent.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdm]
...
show less
Hacking
Web App Attack