๐ฐ๐ท
doll.gl
2026-09-01 09:55:29
(57 minutes ago)
CrowdSec: Ip 136.85.52.249 performed 'crowdsecurity/http-sensitive-files' (5 events over 434.684593m ...
show more
CrowdSec: Ip 136.85.52.249 performed 'crowdsecurity/http-sensitive-files' (5 events over 434.684593ms) at 2026-09-01 09:55:28.913773457 +0000 UTC (scenario: crowdsecurity/http-sensitive-files)
show less
Port Scan
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 09:37:49
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 08:44:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:44:40.052429 2026] [security2:error] [pid 32697:tid 32697] [client 136.85.52.249:36486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sfpantry.noshsf.com"] [uri "/.env.local"] [unique_id "apaQeLWEzOtWoHO6Yc-ALAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:19:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:19:43.789288 2026] [security2:error] [pid 4443:tid 4443] [client 136.85.52.249:55016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mhebert.com"] [uri "/.env"] [unique_id "apaKn2ikzfXaKhYy8EfuXwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 07:52:42
(3 hours ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 07:35:03
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 07:18:09
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-01 07:08:46
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:02:35
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:02:29.194104 2026] [security2:error] [pid 16662:tid 16662] [client 136.85.52.249:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kidswithcamerasmovie.com"] [uri "/.env.old"] [unique_id "apZqdb6vk3t3nLYAsgV7QAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 05:02:16
(5 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 04:05:35
(6 hours ago)
Abuse Detected (3)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:54:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:54:54.439355 2026] [security2:error] [pid 4803:tid 4803] [client 136.85.52.249:43088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jenricker.com"] [uri "/.env.old"] [unique_id "apY-fi-XnHhfU8m4batLcAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:39:00
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:38:55.776291 2026] [security2:error] [pid 16187:tid 16187] [client 136.85.52.249:58900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tinseltownartificials.com"] [uri "/.env.backup"] [unique_id "apY6v5HR_diwxv15_4G3iAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-01 00:36:55
(10 hours ago)
136.85.52.249 - - [01/Sep/2026:02:36:54 +0200] "GET /.env.backup HTTP/1.1" 302 459 "-" "crusader-wor ...
show more
136.85.52.249 - - [01/Sep/2026:02:36:54 +0200] "GET /.env.backup HTTP/1.1" 302 459 "-" "crusader-worker/1.0"
136.85.52.249 - - [01/Sep/2026:02:36:54 +0200] "GET /.env HTTP/1.1" 302 445 "-" "crusader-worker/1.0"
136.85.52.249 - - [01/Sep/2026:02:36:54 +0200] "GET /.env.save HTTP/1.1" 302 455 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 00:14:05
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.52.249 (249.52.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:14:00.937496 2026] [security2:error] [pid 24030:tid 24030] [client 136.85.52.249:57000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blackstarmgmt.net"] [uri "/.env.production"] [unique_id "apYYyL26Dm1y3y4_MqnyxQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack