๐บ๐ธ
TPI-Abuse
2026-08-29 05:03:37
(9 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:03:33.744260 2026] [security2:error] [pid 26181:tid 26181] [client 136.85.32.73:15250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jenssen.silsby.com"] [uri "/@fs/.env"] [unique_id "apJoJaLiLZpiglqYZ0OK3AAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-29 04:43:46
(29 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 03:53:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:53:22.396421 2026] [security2:error] [pid 8558:tid 8558] [client 136.85.32.73:46334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.colorwize.com"] [uri "/@fs/.env"] [unique_id "apJXso25UXimKGqIH18GAwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nightreaver
2026-08-29 03:48:47
(1 hour ago)
136.85.32.73 - - [29/Aug/2026:05:48:47 0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 1024 "-" "Mozil ...
show more
136.85.32.73 - - [29/Aug/2026:05:48:47 0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 1024 "-" "Mozilla/5.0 (compatible; Perplexity-User/1.0; https://perplexity.ai/perplexity-user)"
136.85.32.73 - - [29/Aug/2026:05:48:47 0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 1024 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; https://openai.com/gptbot"
136.85.32.73 - - [29/Aug/2026:05:48:47 0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 1024 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; Claude-User/1.0; https://www.anthropic.com/claude-user) Version/19.6 Safari/605.1.15"
136.85.32.73 - - [29/Aug/2026:05:48:47 0200] "GET /@fs/..%2f..%2f..%2f..%2f..%2fapp/.env?raw?? HTTP/1.1" 404 1024 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; https://www.anthropic.com/claude-searchbot) Chrome/136.0.3116.88 Safari/537.36"
136.85.32.73 - - [2[...]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:52:54
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:52:48.522699 2026] [security2:error] [pid 16122:tid 16122] [client 136.85.32.73:22922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.glentraeger.com"] [uri "/@fs/app/.env"] [unique_id "apJJgGEbDKbLVT2gvKJPKQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 02:39:40
(2 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:34:40
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:34:33.158625 2026] [security2:error] [pid 1782:tid 1782] [client 136.85.32.73:7756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.furballaudio.com"] [uri "/@fs/app/.env"] [unique_id "apJFOczFZwSDulqHNB0--gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
vmd56152.contaboserver.net
2026-08-29 02:30:45
(2 hours ago)
[Sat Aug 29 04:30:26.454423 2026] [core:error] [pid 1435710:tid 140326136444672] [client 136.85.32.7 ...
show more
[Sat Aug 29 04:30:26.454423 2026] [core:error] [pid 1435710:tid 140326136444672] [client 136.85.32.73:50392] AH00126: Invalid URI in request GET /@fs/../../.env?raw?? HTTP/1.1
[Sat Aug 29 04:30:41.978495 2026] [core:error] [pid 760997:tid 140325901297408] [client 136.85.32.73:61708] AH00126: Invalid URI in request GET /@fs/../../../../../app/.env?raw?? HTTP/1.1
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-29 02:12:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:12:43.555318 2026] [security2:error] [pid 14404:tid 14404] [client 136.85.32.73:54400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.watsoncousins.net"] [uri "/@fs/.env"] [unique_id "apJAG410jTLzcc1wxK2_IwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-08-29 01:46:01
(3 hours ago)
2026-08-29 03:44:16 GET /@fs/proc/self/environ?raw?? [301] && 2026-08-29 03:44:16 GET /@fs/app/.env? ...
show more
2026-08-29 03:44:16 GET /@fs/proc/self/environ?raw?? [301] && 2026-08-29 03:44:16 GET /@fs/app/.env?raw?? [301] && 2026-08-29 03:44:16 GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? [301] && 118 more within 20 minutes
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-29 01:33:41
(3 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
mnsf
2026-08-29 01:06:55
(4 hours ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:46:29
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:46:23.817059 2026] [security2:error] [pid 25178:tid 25178] [client 136.85.32.73:14918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oposicionesyconcursos.es"] [uri "/@fs/app/.env"] [unique_id "apIr3_5ZBRRYml1lGYVbrwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:29:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.32.73 (73.32.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:28:54.838705 2026] [security2:error] [pid 4566:tid 4566] [client 136.85.32.73:23372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gdpeters.com"] [uri "/@fs/root/.env"] [unique_id "apInxjww3cHSmegYrBKV3AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-28 23:25:11
(5 hours ago)
Multiple WAF Violations
Web App Attack