๐บ๐ธ
TPI-Abuse
2026-08-28 11:51:23
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:51:15.877270 2026] [security2:error] [pid 5321:tid 5321] [client 136.85.39.170:38300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jimlawless.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apF2MwkHeJF-dVH9TsS-rAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-28 09:44:52
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 09:31:14
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 09:19:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:19:32.528646 2026] [security2:error] [pid 15439:tid 15550] [client 136.85.39.170:54234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dhsandberg.com"] [uri "/@fs/.env"] [unique_id "apFSpD_p6FnXR5XHP7lWNAAAAZA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-28 08:58:11
(11 hours ago)
Automatically blocked due to distributed attack
Hacking
๐ฒ๐พ
Rizzy
2026-08-28 08:56:53
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-28 07:41:15
(12 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 07:05:12
(12 hours ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:01:22
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:01:17.537718 2026] [security2:error] [pid 4759:tid 4759] [client 136.85.39.170:54348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wsdtc.net"] [uri "/@fs/.env"] [unique_id "apEyPbhw9vx1oZgQiZxFOgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-28 06:52:57
(13 hours ago)
Aggressive web search of vulnerable pages: /assets../.env /v1/.env /uploads../.env /v2/.env /.docker ...
show more
Aggressive web search of vulnerable pages: /assets../.env /v1/.env /uploads../.env /v2/.env /.docker/.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:41:51
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.39.170 (170.39.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:41:44.964123 2026] [security2:error] [pid 21400:tid 21400] [client 136.85.39.170:25036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nsmeats.com"] [uri "/@fs/.env.staging"] [unique_id "apEfmAbg5w6lgdhtPwxyHwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 05:30:09
(14 hours ago)
136.85.39.170 - - [28/Aug/2026:07:30:08 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 124 "-" "Mozi ...
show more
136.85.39.170 - - [28/Aug/2026:07:30:08 +0200] "GET /@fs/root/.env?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; TelegramBot/1.0)"
136.85.39.170 - - [28/Aug/2026:07:30:08 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
136.85.39.170 - - [28/Aug/2026:07:30:08 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
136.85.39.170 - - [28/Aug/2026:07:30:08 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.12) Gecko/20100101 Firefox/149.12; compatible; GPTBot/1.4; +https://openai.com/gptbot"
136.85.39.170 - - [28/Aug/2026:07:30:08 +0200] "GET /@fs/home/www-data/.aws/credentials?raw?? HTTP/1.1" 403 124 "-" "Mozilla/5.0
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-08-28 05:29:36
(14 hours ago)
136.85.39.170 (SG/Singapore/170.39.85.136.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐ณ๐ฑ
e.fierstra
2026-08-28 05:28:31
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-08-28 05:21:45
(14 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack