🇺🇸
TPI-Abuse
2026-09-08 12:58:22
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:58:15.762529 2026] [security2:error] [pid 30154:tid 30169] [client 136.85.47.133:19840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mentzlaw.com.aafm.us"] [uri "/@fs/app/.env"] [unique_id "aqAGZ2mV0R0Xx3X-lwclQQAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:37:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:37:46.050388 2026] [security2:error] [pid 27820:tid 27820] [client 136.85.47.133:49644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.misfitranch.com"] [uri "/@fs/.env"] [unique_id "ap_ziljj0qLAvlpROMB6bAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:51:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:51:15.104981 2026] [security2:error] [pid 25832:tid 25832] [client 136.85.47.133:21400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.intelerium.com"] [uri "/@fs/root/.env"] [unique_id "ap_oowDOhGZV0jAs-8ZicwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 10:17:04
(3 hours ago)
136.85.47.133 - - [08/Sep/2026:12:16:22 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 (Macintosh; ...
show more
136.85.47.133 - - [08/Sep/2026:12:16:22 +0200] "GET HTTP/1.1" 403 1852 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot) Chrome/85.0.8207.65 Safari/537.36 Edg
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-08 09:02:02
(4 hours ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [mx01,mx02]
Hacking
SQL Injection
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:59:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:59:39.953948 2026] [security2:error] [pid 3183:tid 3183] [client 136.85.47.133:36708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elgarage.com.mx"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap_OewaiNgH7Fduie3qw4wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-08 08:50:04
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:39:17
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:39:09.103719 2026] [security2:error] [pid 7839:tid 7839] [client 136.85.47.133:29224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.memphislimousines.com"] [uri "/@fs/root/.env"] [unique_id "ap_JrfwetyU8KD3qqHizYgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-08 08:27:49
(5 hours ago)
136.85.47.133 - - [08/Sep/2026:10:27:45 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 771 "-" ...
show more
136.85.47.133 - - [08/Sep/2026:10:27:45 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 771 "-" "Mozilla/5.0 (compatible; GPTBot/1.2; +https://openai.com/gptbot)"
136.85.47.133 - - [08/Sep/2026:10:27:45 +0200] "GET /@fs/home/ubuntu/.aws/config?raw?? HTTP/1.1" 404 771 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
136.85.47.133 - - [08/Sep/2026:10:27:45 +0200] "GET /@fs/root/.aws/config?raw?? HTTP/1.1" 404 771 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
136.85.47.133 - - [08/Sep/2026:10:27:45 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 771 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Twitterbot/1.0"
136.85.47.133 - - [08/Sep/2026:10:27:45 +0200] "GET / HTTP/1.1" 200 1620 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
136.85.47.133 - - [08/Sep/2026:10:27:45 +0200] "GET /@fs/app/.aws/credentia
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 08:16:41
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:16:34.367989 2026] [security2:error] [pid 7014:tid 7014] [client 136.85.47.133:30242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rpmevolution.com.jemsfood.com"] [uri "/@fs/.env"] [unique_id "ap_EYkEa1E_KOyR-BldnSQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:00:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:00:12.058775 2026] [security2:error] [pid 16850:tid 16850] [client 136.85.47.133:22062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pages4you.com"] [uri "/@fs/root/.env"] [unique_id "ap_AjO9pyytWTbmFhrrvSgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:16:35
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.47.133 (133.47.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:16:28.230649 2026] [security2:error] [pid 1714852:tid 1715266] [client 136.85.47.133:46868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.geistmartialarts.com"] [uri "/@fs/.env"] [unique_id "ap-2TBOHGUIw6XcWdwoQuwAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-08 06:17:00
(7 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇷🇺
DZBOT
2026-09-08 05:56:21
(7 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇩🇪
Administrator
2026-09-08 05:52:15
(7 hours ago)
[Tue Sep 08 05:51:57.315077 2026] [php:error] [pid 654476:tid 654476] [client 136.85.47.133:16354] s ...
show more
[Tue Sep 08 05:51:57.315077 2026] [php:error] [pid 654476:tid 654476] [client 136.85.47.133:16354] script '/usr/share/roundcube/wp-config.php' not found or unable to stat
[Tue Sep 08 05:52:03.000103 2026] [php:error] [pid 654472:tid 654472] [client 136.85.47.133:16488] script '/usr/share/roundcube/config.php' not found or unable to stat
[Tue Sep 08 05:52:15.578714 2026] [php:error] [pid 654474:tid 654474] [client 136.85.47.133:1618] script '/usr/share/roundcube/i.php' not found or unable to stat
...
show less
Hacking
Bad Web Bot
Web App Attack