๐บ๐ธ
TPI-Abuse
2026-10-02 05:42:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:42:24.565032 2026] [security2:error] [pid 6205:tid 6205] [client 109.199.155.165:54996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xyncom.com"] [uri "/.env"] [unique_id "ar9EQC6DeL0m6pd6KwI-VgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-10-02 05:35:49
(1 week ago)
Sensitive File Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:23:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:23:17.078514 2026] [security2:error] [pid 21849:tid 21849] [client 109.199.155.165:62823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "talentstar.com"] [uri "/.env"] [unique_id "ar8_xZXyrwxA7lvW5XuM8gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 04:56:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 00:56:01.859546 2026] [security2:error] [pid 28054:tid 28054] [client 109.199.155.165:64570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalunfinishedfurniture.com"] [uri "/.env"] [unique_id "ar85YeVzF76Lc2qY24AtjAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
internetworld
2026-10-02 04:47:59
(1 week ago)
internetworld-prod-01 Fail2Ban ban. Jail=nginx-web-probe-iw. Sanitized automatic report from interne ...
show more
internetworld-prod-01 Fail2Ban ban. Jail=nginx-web-probe-iw. Sanitized automatic report from internetworld.ca server security monitoring.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 04:40:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 00:40:16.191123 2026] [security2:error] [pid 14915:tid 14915] [client 109.199.155.165:54585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barigby.com"] [uri "/.env"] [unique_id "ar81sKw0tWMhUfkfGTwBmQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-10-02 04:10:06
(1 week ago)
blocked for webapp attack | path requested: /.env | seen at 2026-10-02 04:09:07.516 |
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 03:58:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:58:10.950873 2026] [security2:error] [pid 22353:tid 22353] [client 109.199.155.165:62217] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tmarketingproducts.com"] [uri "/.env"] [unique_id "ar8r0mNACGJEU_Bc2YvkVwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 03:41:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:41:37.438295 2026] [security2:error] [pid 27814:tid 27831] [client 109.199.155.165:56857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kettlehill.com"] [uri "/.env"] [unique_id "ar8n8Uaq2CLpmb07sxG_iQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-10-02 03:29:58
(1 week ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 03:22:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:22:25.756035 2026] [security2:error] [pid 24247:tid 24247] [client 109.199.155.165:64772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marionenv.com"] [uri "/.env"] [unique_id "ar8jcbhXOtkG2purhHhZrQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 02:52:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:52:24.579892 2026] [security2:error] [pid 15372:tid 15372] [client 109.199.155.165:51416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acquivest.net"] [uri "/.env"] [unique_id "ar8caLJjZ4N_YnlP-IjEbAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:11:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 109.199.155.165 (23279.telnet.bg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:11:33.082081 2026] [security2:error] [pid 20909:tid 20909] [client 109.199.155.165:54595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestattorneys.com"] [uri "/.env"] [unique_id "ar8ExWacZxzk_PcGk6DQBAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-02 00:53:37
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 0bit.budyn.ovh | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 00:46:39
(1 week ago)
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 109.199.155.165 - - [02/Oct/2026:02:46:28 +0200] "GET /.env HTTP/1.1" 404 6073 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack