🇮🇳
evicky2002
2026-09-10 06:00:02
(5 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇬🇧
openstrike.co.uk
2026-09-09 05:14:27
(6 days ago)
113 attacks on VC URLs, env grabbing URLs (type 2), PHP URLs, env grabbing URLs, password/key grabbi ...
show more
113 attacks on VC URLs, env grabbing URLs (type 2), PHP URLs, env grabbing URLs, password/key grabbing URLs, config grabbing URLs (type 2):
GET /.git/HEAD HTTP/1.1
GET /@fs/proc/self/cwd/.config/gcloud/application_default_credentials.json?raw?? HTTP/1.1
GET /pi.php HTTP/1.1
GET /.env~ HTTP/1.1
GET /id_ed25519 HTTP/1.1
GET /auth.json HTTP/1.1
show less
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-08 22:02:09
(6 days ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇺🇸
[email protected]
2026-09-08 12:36:55
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-08T12:36:55Z
Brute-Force
🇺🇸
[email protected]
2026-09-08 11:24:59
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-08T11:24:59Z
Brute-Force
🇺🇸
ruusvuu
2026-09-08 10:49:37
(6 days ago)
Automated abuse report: 25 attack/probe requests from Google LLC / SG.
Targeted paths: /@fs/..%252f. ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / SG.
Targeted paths: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ, /@fs/etc/passwd, /@fs/proc/self/environ, /@fs/proc/self/cmdline, /@fs/app/gcp-credentials.json.
Sample log lines:
[splitser] 136.85.77.141 - [08/Sep/2026:10:49:35 +0000] "GET /@fs/root/.config/gcloud/credentials.db?raw??" 404 "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +h…
[splitser] 136.85.77.141 - [08/Sep/2026:10:49:35 +0000] "GET /@fs/root/.config/gcloud/application_default_credentials.json?raw??" 404 "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; …
[splitser] 136.85.77.141 - [08/Sep/2026:10:49:35 +0000] "GET /@fs/var/run/secrets/kubernetes.io/serviceaccount/token?raw??" 404 "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-…
Detected by an automated web-server log monitor.
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-08 10:13:58
(6 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:21:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.77.141 (141.77.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.77.141 (141.77.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:21:04.558083 2026] [security2:error] [pid 3426:tid 3426] [client 136.85.77.141:4282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.genesis-group.net"] [uri "/@fs/app/.env"] [unique_id "ap_TgGPs6iiXCJ-jjj6d8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
[email protected]
2026-09-08 09:07:18
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-08T09:07:18Z
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 07:59:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.77.141 (141.77.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.77.141 (141.77.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:59:45.164125 2026] [security2:error] [pid 10720:tid 10720] [client 136.85.77.141:37134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.belize-boat-registration.com"] [uri "/@fs/root/.env"] [unique_id "ap_AcQBMtFNuDeSps_QxvgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
[email protected]
2026-09-08 07:53:50
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-08T07:53:50Z
Brute-Force
🇦🇺
AWW-Admin
2026-09-08 07:17:33
(6 days ago)
(mod_security) mod_security triggered on hostname [redacted] 136.85.77.141 (SG/Singapore/141.77.85.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.85.77.141 (SG/Singapore/141.77.85.136.bc.googleusercontent.com)
show less
SQL Injection
🇬🇧
consul.to
2026-09-08 07:14:29
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
🇪🇸
pipeline.es
2026-09-08 07:14:19
(6 days ago)
Web scanning / probing for vulnerable paths | URL: /@fs/var/task/.env?raw?? | Evidence: microsites.a ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/var/task/.env?raw?? | Evidence: microsites.aavv.com 136.85.77.141 - - [08/Sep/2026:09:13:47 +0200] \"GET /@fs/var/task/.env?raw?? HTTP/1.1\" 404 3760 \"-\" \"Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇺🇸
[email protected]
2026-09-08 06:48:54
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-08T06:48:54Z
Brute-Force