This IP address has been reported a total of
48
times from
31 distinct
sources.
85.121.127.138 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
[SunJun0700:05:49.9128722026][security2:error][pid4164655:tid4165137][client85.121.127.138:0]ModSecu ...
show more[SunJun0700:05:49.9128722026][security2:error][pid4164655:tid4165137][client85.121.127.138:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"fondazionemontgrand.ch\"][uri\"/.aws/credentials\"][unique_id\"aiSZvUt45wkZ-cxGfgTF2AAAAEU\"]
show less
(mod_security) mod_security (id:210492) triggered by 85.121.127.138 (-): 1 in the last 300 secs; Por ...
show more(mod_security) mod_security (id:210492) triggered by 85.121.127.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 15:46:24.903826 2026] [security2:error] [pid 2569:tid 2569] [client 85.121.127.138:35160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluff.thewaywework.com"] [uri "/.git/config"] [unique_id "aiR5EGrV_NCYV21WxFkxqgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
Bot / scanning and/or hacking attempts: GET /api/settings HTTP/2.0, GET /config.env HTTP/2.0, GET /c ...
show moreBot / scanning and/or hacking attempts: GET /api/settings HTTP/2.0, GET /config.env HTTP/2.0, GET /config.json HTTP/2.0, GET /.env.production HTTP/2.0, GET /api/v1/settings HTTP/2.0, GET /server.env HTTP/2.0, GET /config/application.properties HTTP/2.0, GET /config.js HTTP/2.0, GET /.env.bak HTTP/2.0, GET /asset-manifest.json HTTP/2.0, [31/30] done: stream 61, GET /.ssh/id_ed25519, GET /.env.backup HTTP/2.0, GET /.env.docker HTTP/2.0, GET /.env.old HTTP/2.0, GET /.env.example HTTP/2.0, GET /__/firebase/init.json HTTP/2.0, GET /public/.env HTTP/2.0, GET /manifest.json HTTP/2.0, GET /build-manifest.json HTTP/2.0
show less
Hacking
Web App Attack
Showing 1 to
15
of 48 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ