πͺπΈ
robotstxt
2026-09-29 13:18:22
(1 day ago)
136.92.6.17 - - [29/Sep/2026:13:17:19 +0000] "GET /.env HTTP/1.1" 403 18048 "-" "Mozilla/5.0 (Macint ...
show more
136.92.6.17 - - [29/Sep/2026:13:17:19 +0000] "GET /.env HTTP/1.1" 403 18048 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="136.92.6.17"
136.92.6.17 - - [29/Sep/2026:13:17:19 +0000] "GET /.env.local HTTP/1.1" 403 18048 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="136.92.6.17"
136.92.6.17 - - [29/Sep/2026:13:17:19 +0000] "GET /.env.production HTTP/1.1" 403 18048 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="136.92.6.17"
136.92.6.17 - - [29/Sep/2026:13:17:20 +0000] "GET /.env.staging HTTP/1.1" 403 18048 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="136.92.6.17"
136.92.6.17 - - [29/Sep/2026:13:17:20 +0000] "GET /.env.development HTTP/1.1" 403 1
...
show less
Web App Attack
π©πͺ
R.G.
2026-09-29 05:53:37
(1 day ago)
(ScanningForFiles) Scanning for files triggerd 136.92.6.17 (DE/Germany/17.6.92.136.bc.googleusercont ...
show more
(ScanningForFiles) Scanning for files triggerd 136.92.6.17 (DE/Germany/17.6.92.136.bc.googleusercontent.com): 10 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-09-29 05:15:40
(1 day ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/17.6.92.136.bc.googleusercontent. ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/17.6.92.136.bc.googleusercontent.com
show less
Web App Attack
π«π·
dynamix
2026-09-28 23:50:11
(1 day ago)
Multiple WAF Violations
Web App Attack
π©πͺ
ghostwarriors
2026-09-28 05:50:18
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 05:48:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.92.6.17 (17.6.92.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.6.17 (17.6.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:48:37.969858 2026] [security2:error] [pid 29257:tid 29257] [client 136.92.6.17:60938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frankweyer.com"] [uri "/.git/config"] [unique_id "arn_tYWQv9Rwp-SsYsjPRAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
yitzhaq
2026-09-28 05:44:31
(2 days ago)
136.92.6.17 - - [28/Sep/2026:07:44:29 +0200] "GET /cache/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Wi ...
show more
136.92.6.17 - - [28/Sep/2026:07:44:29 +0200] "GET /cache/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.92.6.17 - - [28/Sep/2026:07:44:29 +0200] "GET /mailer/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.92.6.17 - - [28/Sep/2026:07:44:29 +0200] "GET /mail/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.92.6.17 - - [28/Sep/2026:07:44:29 +0200] "GET /email/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.92.6.17 - - [28/Sep/2026:07:44:29 +0200] "GET /smtp/.env HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
136.92.6.17
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-28 04:51:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.92.6.17 (17.6.92.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.6.17 (17.6.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 00:51:26.377982 2026] [security2:error] [pid 1871:tid 1871] [client 136.92.6.17:37502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frankperras.com"] [uri "/.git/config"] [unique_id "arnyTpZ-2rAxzARYWXKcWAAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 04:20:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 136.92.6.17 (17.6.92.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.92.6.17 (17.6.92.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 00:20:03.199742 2026] [security2:error] [pid 16863:tid 16863] [client 136.92.6.17:38590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "franklycommerce.com"] [uri "/.git/config"] [unique_id "arnq8wcCzrXP59liZX-TKwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Bedios GmbH
2026-09-24 16:24:45
(6 days ago)
Login credentials theft attempt
Hacking
π©πͺ
kivitendo.de
2026-09-24 13:31:08
(6 days ago)
[Thu Sep 24 15:31:11.017696 2026] [access_compat:error] [pid 67879:tid 67891] [client 136.92.6.17:47 ...
show more
[Thu Sep 24 15:31:11.017696 2026] [access_compat:error] [pid 67879:tid 67891] [client 136.92.6.17:47676] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/config
[Thu Sep 24 15:31:11.395114 2026] [access_compat:error] [pid 67879:tid 67888] [client 136.92.6.17:47676] AH01797: client denied by server configuration: /var/www/kivitendo-erp/config/.env
...
show less
Brute-Force
Web App Attack
π©πͺ
mondor.ro
2026-09-24 03:33:19
(6 days ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 136.92.6.17, Reason:[( ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 136.92.6.17, Reason:[(mod_security) mod_security (id:210492) triggered by 136.92.6.17 (DE/Germany/17.6.92.136.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
π¦πΊ
screwlooseit.com.au
2026-09-24 02:05:02
(6 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/17.6.92.136.bc.googleusercontent. ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/17.6.92.136.bc.googleusercontent.com
show less
Web App Attack
π«π·
masterguru
2026-09-24 01:08:18
(6 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
πΊπΈ
dot.mg
2026-09-24 00:50:02
(6 days ago)
Bad behaviour
Web Spam