๐บ๐ธ
TPI-Abuse
2026-07-31 02:47:10
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 22:47:06.782416 2026] [security2:error] [pid 2059750:tid 2059750] [client 136.85.61.2:52894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goomapush.com"] [uri "/.env"] [unique_id "amwMqq_H0oD8se5SaCp4BAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-31 02:26:11
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 02:10:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 22:10:13.029534 2026] [security2:error] [pid 2453022:tid 2453022] [client 136.85.61.2:22060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kildarafarms.com"] [uri "/.env.production"] [unique_id "amwEBYbUk9zlpCJSCwVSRgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-31 01:48:41
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-07-31 01:36:06
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 00:58:37
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 20:58:32.959788 2026] [security2:error] [pid 1028606:tid 1028606] [client 136.85.61.2:27520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.yarbroughfamily.org"] [uri "/.env.backup"] [unique_id "amvzOFlzpczEpPCmzZTqsgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 00:09:39
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 20:09:34.212760 2026] [security2:error] [pid 3022398:tid 3022398] [client 136.85.61.2:34346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.noisepie.com"] [uri "/.env"] [unique_id "amvnvjG6q06ByX3kkgGTpQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 00:07:30
(3 hours ago)
Aggressive web scan
Web App Attack
Anonymous
2026-07-31 00:07:04
(3 hours ago)
Bot / scanning and/or hacking attempts: GET /secrets.yml HTTP/1.1, GET /web.config HTTP/1.1, GET /bo ...
show more
Bot / scanning and/or hacking attempts: GET /secrets.yml HTTP/1.1, GET /web.config HTTP/1.1, GET /bootstrap.yml HTTP/1.1, GET /secrets.yaml HTTP/1.1, GET /configuration.php HTTP/1.1, GET /config.php.bak HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /wp-config.php.orig HTTP/1.1, GET /config/application.yml HTTP/1.1, GET /config.ini HTTP/1.1, GET /appsettings.Development.json HTTP/1.1, GET /config/config.php HTTP/1.1, GET /.cursor/mcp.json HTTP/1.1, GET /settings.py HTTP/1.1, GET /docker-compose.yaml HTTP/1.1, GET /.openclaw/agents/main/agent/models.json HTTP/1.1, GET /config.yml HTTP/1.1, GET /.yarnrc HTTP/1.1, GET /config.toml HTTP/1.1, GET /backend/aws.json HTTP/1.1, GET /application.yaml HTTP/1.1, GET /wp-config.php.old HTTP/1.1, GET /local_settings.py HTTP/1.1, GET /wp-config.php.save HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 23:52:12
(3 hours ago)
203 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-30 23:21:39
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 19:21:35.130170 2026] [security2:error] [pid 1461264:tid 1461264] [client 136.85.61.2:14872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixals.net"] [uri "/.env.staging"] [unique_id "amvcf2ZVt0u7h0hJ5UmL6AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-07-30 23:17:39
(4 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;URL file extension is rest ...
show more
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack
๐ง๐ท
vfAcceloReporter
2026-07-30 23:13:12
(4 hours ago)
136.85.61.2 - - [30/Jul/2026:20:13:11 -0300] "GET /.env HTTP/1.1" 404 125 "-" "TLM-Audit-Scanner/1.0 ...
show more
136.85.61.2 - - [30/Jul/2026:20:13:11 -0300] "GET /.env HTTP/1.1" 404 125 "-" "TLM-Audit-Scanner/1.0"
136.85.61.2 - - [30/Jul/2026:20:13:11 -0300] "GET /api/.env HTTP/1.1" 404 125 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)"
136.85.61.2 - - [30/Jul/2026:20:13:11 -0300] "GET /.env.bak HTTP/1.1" 404 125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
136.85.61.2 - - [30/Jul/2026:20:13:11 -0300] "GET /env.json HTTP/1.1" 404 125 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
136.85.61.2 - - [30/Jul/2026:20:13:11 -0300] "GET /.gcloud/credentials.json HTTP/1.1" 404 125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
...
show less
Brute-Force
Web App Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-30 22:33:09
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.61.2 (2.61.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 18:33:05.164137 2026] [security2:error] [pid 12409:tid 12425] [client 136.85.61.2:27378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.robertbellamystudio.com"] [uri "/.env.development"] [unique_id "amvRIUkil9XucMH1HFkcrQAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
itsnixk
2026-07-30 22:10:14
(5 hours ago)
(mod_security) mod_security (id:930130) triggered by 136.85.61.2 (SG/Singapore/2.61.85.136.bc.google ...
show more
(mod_security) mod_security (id:930130) triggered by 136.85.61.2 (SG/Singapore/2.61.85.136.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Thu Jul 30 18:10:08.467498 2026] [security2:error] [pid 92653:tid 92679] [remote 136.85.61.2:0] ModSecurity: Access denied with code 406 (phase 1). Matched phrase ".env" at REQUEST_FILENAME. [file "/etc/modsecurity.d/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "150"] [id "930130"] [msg "Restricted File Access Attempt"] [redacted] [severity "CRITICAL"] [ver "OWASP_CRS/4.28.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [redacted] [uri "/.env"] [unique_id "amvLwOaTSpgt2lADzFlSUgAAcRg"]
show less
Port Scan