🇺🇸
TPI-Abuse
2026-09-04 15:16:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:15:52.842161 2026] [security2:error] [pid 17772:tid 17772] [client 136.85.90.211:55502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.abakada.net"] [uri "/wp-config.php~"] [unique_id "aprgqOO--BqhtDNy3EGHIgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:08:05
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:59.763520 2026] [security2:error] [pid 31832:tid 31832] [client 136.85.90.211:54350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whatcausesmentalillness.com"] [uri "/.env"] [unique_id "aprQvyEh1Lvz3XsxcUTL8gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-04 12:32:31
(3 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:53:05
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:52:59.335564 2026] [security2:error] [pid 20758:tid 20758] [client 136.85.90.211:36380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magiapedia.magodarman.com"] [uri "/.env.backup"] [unique_id "apqxG6aFEtkxb_UNjd8RMAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 11:20:07
(5 hours ago)
[04/Sep/2026:14:20:06 +0300] -- 136.85.90.211 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[04/Sep/2026:14:20:06 +0300] -- 136.85.90.211 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.local HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:55:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:55:12.859991 2026] [security2:error] [pid 1179:tid 1179] [client 136.85.90.211:57442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigheartskitchen.com"] [uri "/.env.dev"] [unique_id "apqjkLWRH6zPCF63r1bsEQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-04 10:41:02
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:11:47
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:11:42.532278 2026] [security2:error] [pid 21834:tid 21834] [client 136.85.90.211:45332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lemoulinavent.org"] [uri "/.env.backup"] [unique_id "apqLTp457B-bDqIYPv6h3AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-04 08:21:43
(8 hours ago)
80,443
Brute-Force
SSH
🇺🇸
mnsf
2026-09-04 08:05:26
(8 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 08:00:23
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-04 07:43:59
(8 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-193)
Hacking
🇺🇸
TPI-Abuse
2026-09-04 07:34:28
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.85.90.211 (211.90.85.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:34:23.867725 2026] [security2:error] [pid 17428:tid 17484] [client 136.85.90.211:34016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toubaomaha.com"] [uri "/.env.backup"] [unique_id "app0fzSx8e8r70msEhGrzQAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 06:30:09
(9 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-04 05:37:54
(10 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.85.90.211 (SG/Singapore/211.90.85.136.bc ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 136.85.90.211 (SG/Singapore/211.90.85.136.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.85.90.211 - - [04/Sep/2026:07:37:52 +0200] "GET /.env.local HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
136.85.90.211 - - [04/Sep/2026:07:37:52 +0200] "GET /.env.example HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
136.85.90.211 - - [04/Sep/2026:07:37:52 +0200] "GET /.env.dev HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan