π³π±
Site.eu
2026-08-31 00:35:30
(1 month ago)
Excessive multi-domain requests
Brute-Force
π¬π§
openstrike.co.uk
2026-08-29 05:13:52
(1 month ago)
138 attacks on env grabbing URLs, VC URLs, PHP URLs, config grabbing URLs (type 2), password grabbin ...
show more
138 attacks on env grabbing URLs, VC URLs, PHP URLs, config grabbing URLs (type 2), password grabbing URLs:
GET /aws/.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /config/aws.php HTTP/1.1
GET /config/aws.json HTTP/1.1
GET /.aws/credentials.old HTTP/1.1
show less
Hacking
Web App Attack
π·πΊ
DZBOT
2026-08-28 13:35:07
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π³π±
middelkoopcc
2026-08-28 13:27:00
(1 month ago)
2026-08-28 15:25:06 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-08-28 15:25:18 AH10244 ...
show more
2026-08-28 15:25:06 AH10244: invalid URI path (/@fs/../../.env?raw??) && 2026-08-28 15:25:18 AH10244: invalid URI path (/@fs/../../../../../root/.env?raw??) && 2026-08-28 15:25:18 AH10244: invalid URI path (/@fs/../../../../../proc/self/environ?raw??) && 134 more within 20 minutes
show less
Web App Attack
Anonymous
2026-08-28 12:33:00
(1 month ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 12:11:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:11:17.246677 2026] [security2:error] [pid 25638:tid 25638] [client 136.85.53.247:57304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ospreylake.org"] [uri "/@fs/app/.env"] [unique_id "apF65ejG3XolnKjDPHO4aQAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 12:07:41
(1 month ago)
Web scanner: GET /@fs/.env?raw??
Web App Attack
Hacking
πΊπΈ
wordpresshosting.solutions
2026-08-28 11:27:43
(1 month ago)
Web app vulnerability scanning detected. Evidence: 136.85.53.247 - - [28/Aug/2026:11:27:42 +0000] "G ...
show more
Web app vulnerability scanning detected. Evidence: 136.85.53.247 - - [28/Aug/2026:11:27:42 +0000] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 404 50201 "https://[DOMAIN]/@fs/home/ubuntu/.aws/credentials?raw??" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
136.85.53.247 - - [28/Aug/2026:11:27:42 +0000] "GET /@fs/home/node/.aws/config?raw?? HTTP/1.1" 404 50187 "https://[DOMAIN]/@fs/home/node/.aws/config?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GrokBot/1.0; +https://x.ai/grokbot"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 11:27:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:27:29.964867 2026] [security2:error] [pid 10435:tid 10435] [client 136.85.53.247:44894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.callalbany.com"] [uri "/@fs/app/.env"] [unique_id "apFwoZYISrVvCY2YgRRtfAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 11:06:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:05:57.726844 2026] [security2:error] [pid 31332:tid 31356] [client 136.85.53.247:52078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cargostuff.com"] [uri "/@fs/.env"] [unique_id "apFrldIJLbbYmwMqD03QSAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 11:00:18
(1 month ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
Anonymous
2026-08-28 10:02:58
(1 month ago)
Web attack
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2026-08-28 09:12:02
(1 month ago)
136.85.53.247 - - [28/Aug/2026:03:11:47 -0600] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
...
show more
136.85.53.247 - - [28/Aug/2026:03:11:47 -0600] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
136.85.53.247 - - [28/Aug/2026:03:12:02 -0600] "GET /@fs/../../../../../proc/self/environ?raw?? HTTP/1.1" 400 150 "-" "-"
136.85.53.247 - - [28/Aug/2026:03:12:02 -0600] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 400 150 "-" "-"
136.85.53.247 - - [28/Aug/2026:03:12:02 -0600] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 150 "-" "-"
136.85.53.247 - - [28/Aug/2026:03:12:02 -0600] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 08:49:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:49:25.525940 2026] [security2:error] [pid 743681:tid 744349] [client 136.85.53.247:52842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kwainet.com"] [uri "/@fs/.env"] [unique_id "apFLlazKk__5QR0Jy--y3QAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 07:05:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.53.247 (247.53.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:05:53.148438 2026] [security2:error] [pid 4723:tid 4723] [client 136.85.53.247:53340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tankservicesinc.com"] [uri "/@fs/root/.env"] [unique_id "apEzUbEZybQelMDViMlelwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack