This IP address has been reported a total of
34
times from
27 distinct
sources.
141.136.43.123 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
Reporter
IoA Timestamp (UTC)
Comment
Categories
Anonymous
(caddyscan) Scanner path probe from 141.136.43.123 (GB/United Kingdom/-): 5 in the last 3600 secs; P ...
show more(caddyscan) Scanner path probe from 141.136.43.123 (GB/United Kingdom/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 141.136.43.123 - - [08/Jun/2026:07:38:59 +0000] "GET /members/.env HTTP/1.1"
[REDACTED] 200 2627 141.136.43.123 - - [08/Jun/2026:07:38:59 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 141.136.43.123 - - [08/Jun/2026:07:38:59 +0000] "GET /laravel/.env HTTP/1.1"
[REDACTED] 200 2627 141.136.43.123 - - [08/Jun/2026:07:38:59 +0000] "GET /api/.env.save HTTP/1.1"
[REDACTED] 200 2627 141.136.43.123 - - [08/Jun/2026:07:38:59 +0000] "GET /dev/.env HTTP/1.1"
show less
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(๐พ - ๐จ Network ๐ต sc ...
show moreThis IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(๐พ - ๐จ Network ๐ต scan ๐ฉ Nuclei ๐จโ๐ป). Ip 141.136.43.123 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2026-06-08 07:09:07.497850186 +0000 UTC
show less
[MonJun0807:29:52.5449302026][security2:error][pid723509:tid723545][client141.136.43.123:0]ModSecuri ...
show more[MonJun0807:29:52.5449302026][security2:error][pid723509:tid723545][client141.136.43.123:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"bicycleambulance.ch\"][uri\"/api/.env\"][unique_id\"aiZTUJQZTKL5zbq0GA8-UQAAABg\"]
show less
http-sensitive-files - IP: 141.136.43.123 - time="2026-06-08T06:49:55+02:00" level=info msg="(555f6 ...
show morehttp-sensitive-files - IP: 141.136.43.123 - time="2026-06-08T06:49:55+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 141.136.43.123 (GB/47583) : 4h ban on Ip 141.136.43.123" module=db
show less
[MonJun0806:49:16.6437542026][security2:error][pid2507445:tid2507766][client141.136.43.123:0]ModSecu ...
show more[MonJun0806:49:16.6437542026][security2:error][pid2507445:tid2507766][client141.136.43.123:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"fimka-icp.com\"][uri\"/members/.env\"][unique_id\"aiZJzJ6yuhvJc_BhlLZ59QAAAQg\"]
show less
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show moreFail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less