🇩🇪
palzer.IT
2026-09-08 12:05:56
(9 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 136.85.81.181 - - [08/Sep/2026:14:05:39 +0200] GE ...
show more
Fail2ban automatic report for plesk-apache-badbot: 136.85.81.181 - - [08/Sep/2026:14:05:39 +0200] GET /@fs/root/.aws/config?raw?? [DOMAIN_REMOVED] 301 5839 [DOMAIN_REMOVED] Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +[DOMAIN_REMOVED]
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 10:34:18
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:34:10.199191 2026] [security2:error] [pid 3775:tid 3775] [client 136.85.81.181:5024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hierarchyofvalues.org"] [uri "/@fs/.env"] [unique_id "ap_konhN882lQ14YxltfcgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 08:38:17
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:39:00
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:38:54.713996 2026] [security2:error] [pid 17835:tid 17835] [client 136.85.81.181:37770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cwchamber.com"] [uri "/@fs/.env"] [unique_id "ap-tfvOCiL6wy8CLE0nQ4QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 06:34:42
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Site.eu
2026-09-08 06:04:57
(15 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-08 05:24:04
(16 hours ago)
136.85.81.181 - - [08/Sep/2026:07:23:26 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKit ...
show more
136.85.81.181 - - [08/Sep/2026:07:23:26 +0200] "GET HTTP/1.1" 403 1856 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇩🇪
todix
2026-09-08 05:21:15
(16 hours ago)
Web App Attack Exploid from 136.85.81.181
Web App Attack
🇲🇾
Rizzy
2026-09-08 05:18:59
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:15:19
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:15:11.712227 2026] [security2:error] [pid 26321:tid 26321] [client 136.85.81.181:22822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penjoki.us"] [uri "/@fs/.env"] [unique_id "ap-Z3-nTNTD8rN4SQB16ZQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-08 05:14:05
(16 hours ago)
129 attacks on VC URLs, env grabbing URLs, config grabbing URLs (type 2), password/key grabbing URLs ...
show more
129 attacks on VC URLs, env grabbing URLs, config grabbing URLs (type 2), password/key grabbing URLs, PHP URLs, env grabbing URLs (type 2):
GET /.git/HEAD HTTP/1.1
GET /client/.env HTTP/1.1
GET /appsettings.json HTTP/1.1
GET /id_rsa HTTP/1.1
GET /pi.php HTTP/1.1
GET /@fs/proc/self/cwd/.azure/credentials?raw?? HTTP/1.1
show less
Hacking
Web App Attack
🇩🇪
FD-IX
2026-09-08 04:59:03
(16 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:51:09
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:51:04.090327 2026] [security2:error] [pid 26499:tid 26499] [client 136.85.81.181:62632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.grasslakepizzatime.com"] [uri "/@fs/root/.env"] [unique_id "ap-UOE6YNhQVS9ISSM_NmgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:35:32
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.81.181 (181.81.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:35:25.711513 2026] [security2:error] [pid 4154:tid 4191] [client 136.85.81.181:57692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.sandiegosamsolo.com"] [uri "/@fs/root/.env"] [unique_id "ap-QjU-YlZNbSYcVbqa3XAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-08 04:29:23
(17 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack