๐บ๐ธ
TPI-Abuse
2026-09-29 07:04:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:04:16.617396 2026] [security2:error] [pid 28149:tid 28182] [client 136.85.86.16:58246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americanacademyofprojectmanagement.com"] [uri "/.git/config"] [unique_id "arti8CJ1olh01O22fHH7QAAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Webmestre
2026-09-28 13:51:00
(4 days ago)
Attempt to access non-existent PHP and WordPress pages /.env /wp-admin/
Bad Web Bot
Web App Attack
Hacking
๐จ๐ฆ
Anytech
2026-09-28 03:23:48
(5 days ago)
Blocked by ConnMonitor
Web App Attack
๐ต๐ฑ
Bonn333
2026-09-28 02:31:52
(5 days ago)
CrowdSec: probing for exposed secrets and config files. Scenario=crowdsecurity/http-sensitive-files; ...
show more
CrowdSec: probing for exposed secrets and config files. Scenario=crowdsecurity/http-sensitive-files; events=5; window=2026-09-28T02:31:49.222192382Z .. 2026-09-28T02:31:51.422544883Z. Tried: GET /.git/config | GET /.env | GET /.env.local | GET /.env.staging | GET /.env.development. Automated report, no manual review.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-26 08:02:13
(1 week ago)
Web attack
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-25 19:28:59
(1 week ago)
3.449 requests with url.path *.env
559 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 23:27:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:27:24.855033 2026] [security2:error] [pid 21511:tid 21511] [client 136.85.86.16:37028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amyisms.com"] [uri "/.git/config"] [unique_id "arG9XL76Esk6MsSoEhaq4wAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:44:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:44:51.823819 2026] [security2:error] [pid 9597:tid 9597] [client 136.85.86.16:50788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amybeam.com"] [uri "/.git/config"] [unique_id "arGzY68YY4RzRt6XaRub1AAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Kreapptivo
2026-09-21 15:14:18
(1 week ago)
136.85.86.16 - [2026-09-21T17:14:14+02:00] "POST / HTTP/1.1" 400 "code=400, message=missing or malf ...
show more
136.85.86.16 - [2026-09-21T17:14:14+02:00] "POST / HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "" 31690
136.85.86.16 - [2026-09-21T17:14:14+02:00] "GET /.env HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "" 36099
136.85.86.16 - [2026-09-21T17:14:14+02:00] "GET /.env.local HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "" 32673
136.85.86.16 - [2026-09-21T17:14:15+02:00] "GET /.env.production HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKi
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 19:09:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.86.16 (16.86.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:09:44.604598 2026] [security2:error] [pid 20961:tid 20984] [client 136.85.86.16:34606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stonyp.com"] [uri "/.git/config"] [unique_id "arAveIrWZ5CnQ6_3hcfQ2AAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 13:35:04
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack