๐ซ๐ท
UnixPrime
2026-09-19 14:49:28
(4 hours ago)
136.85.40.238 - - [19/Sep/2026:16:49:27 +0200] "GET /.env.local?raw HTTP/1.1" 404 118 "-" "Mozilla/5 ...
show more
136.85.40.238 - - [19/Sep/2026:16:49:27 +0200] "GET /.env.local?raw HTTP/1.1" 404 118 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
136.85.40.238 - - [19/Sep/2026:16:49:27 +0200] "GET /.env?raw HTTP/1.1" 404 118 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 02:23:14
(17 hours ago)
[19/Sep/2026:05:23:13 +0300] 178978459357.137436 136.85.40.238 57812 148.251.76.218 443
[19/Sep/2026 ...
show more
[19/Sep/2026:05:23:13 +0300] 178978459357.137436 136.85.40.238 57812 148.251.76.218 443
[19/Sep/2026:05:23:13 +0300] 178978459317.706677 136.85.40.238 57812 148.251.76.218 443
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-18 05:55:03
(1 day ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
Anonymous
2026-09-18 00:55:45
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ธ๐ช
vaia.cloud
2026-09-17 23:50:02
(1 day ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:15:55
(1 day ago)
Brute-Force
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-17 20:00:53
(1 day ago)
Active Response: IP 136.85.40.238 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: ...
show more
Active Response: IP 136.85.40.238 Blocked via Firewall Drop. Threat Score: 3.9/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 16:02:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.40.238 (238.40.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.40.238 (238.40.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:02:27.332653 2026] [security2:error] [pid 25196:tid 25196] [client 136.85.40.238:37560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.acupressbooks.com"] [uri "/@fs/src/.env"] [unique_id "aqwPExEpyv7IHYAeHjrDRAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
swiszczu
2026-09-17 14:07:47
(2 days ago)
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
136.85.40.238 - - [1 ...
show more
Fail2Ban automatic report:
Multiple forbidden requests in short amount of time:
136.85.40.238 - - [17/Sep/2026:16:07:44 +0200] "GET /.github/.env HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-"
136.85.40.238 - - [17/Sep/2026:16:07:44 +0200] "GET /.docker/config.json HTTP/2.0" 403 153 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-"
136.85.40.238 - - [17/Sep/2026:16:07:44 +0200] "GET /.s3cfg HTTP/2.0" 403 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-"
136.85.40.238 - - [17/Sep/2026:16:07:44 +0200] "GET /.htpasswd HTTP/2.0" 403 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-"
136.85.40.238 - - [17/Sep/2026:16:07:44 +0200]
show less
Hacking
Web App Attack
๐ฌ๐ง
Marten Mark
2026-09-17 13:58:12
(2 days ago)
136.85.40.238 - - [17/Sep/2026:13:58:05 +0000] "GET /.gradle/gradle.properties HTTP/2.0" 404 1449 "- ...
show more
136.85.40.238 - - [17/Sep/2026:13:58:05 +0000] "GET /.gradle/gradle.properties HTTP/2.0" 404 1449 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
136.85.40.238 - - [17/Sep/2026:13:58:06 +0000] "GET /config/storage.yml HTTP/2.0" 404 1452 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
136.85.40.238 - - [17/Sep/2026:13:58:06 +0000] "GET /config/storage.yml HTTP/2.0" 404 1452 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
136.85.40.238 - - [17/Sep/2026:13:58:06 +0000] "GET /.streamlit/secrets.toml HTTP/2.0" 404 1452 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
136.85.40.238 - - [17/Sep/2026:13:58:06 +0000] "GET /.streamlit/secrets.toml HTTP/2.0" 404 1452 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
136.85.40.238 - - [17/Sep/2026:13:58:07 +0000] "GET /.env.development
...
show less
Port Scan
Web App Attack
๐ฎ๐น
Inartis
2026-09-17 11:46:35
(2 days ago)
136.85.40.238 - - [17/Sep/2026:13:46:34 +0200] "GET /.env.old HTTP/2.0" 403 17 "-" "Mozilla/5.0 (com ...
show more
136.85.40.238 - - [17/Sep/2026:13:46:34 +0200] "GET /.env.old HTTP/2.0" 403 17 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 11:32:26
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 11:30:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.40.238 (238.40.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.40.238 (238.40.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:29:59.669889 2026] [security2:error] [pid 24568:tid 24568] [client 136.85.40.238:52094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beta.flavornet.org"] [uri "/admin/.env"] [unique_id "aqvPNyUk0oWU4y7DjGy3WwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
anan17
2026-09-17 11:25:37
(2 days ago)
Vulnerability scanner probing sensitive paths (/.env, AWS credentials, Kubernetes tokens, /icecoder/ ...
show more
Vulnerability scanner probing sensitive paths (/.env, AWS credentials, Kubernetes tokens, /icecoder/lib/terminal-xhr.php) using spoofed bot User-Agents
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 07:34:54
(2 days ago)
malicious scanning tool activity
Web App Attack