๐ต๐ฑ
Budyn
2026-08-29 04:45:51
(20 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.pro | URI: /@fs/home/www-data/.aws/credentials?raw?? | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.4) Gecko/20100101 Firefox/150.4; compatible; Applebot/0.1; +http://www.apple.com/go/applebot | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:09:07
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:09:01.115468 2026] [security2:error] [pid 30724:tid 30724] [client 136.110.116.228:9704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.twilighthackers.com"] [uri "/@fs/.env"] [unique_id "apJbXTJ4yJEhpW7aChJIzwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-29 02:50:58
(2 hours ago)
20 attempts against mh_ha-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:36:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:36:12.918514 2026] [security2:error] [pid 26523:tid 26523] [client 136.110.116.228:21862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.stkm.com"] [uri "/@fs/root/.env"] [unique_id "apJFnKbp66w4IMlHY1wPwgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-29 02:36:04
(2 hours ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 7s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:18:50
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:18:45.210896 2026] [security2:error] [pid 31960:tid 31960] [client 136.110.116.228:61324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.firstclasstreatment.com"] [uri "/@fs/src/.env"] [unique_id "apJBhYHXBCGcYEWZOpBVwAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:56:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:55:55.773437 2026] [security2:error] [pid 14053:tid 14268] [client 136.110.116.228:38182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.trejbal.com"] [uri "/@fs/root/.env"] [unique_id "apI8KxV5cF-sF0zurkXAHQAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-29 01:53:35
(3 hours ago)
Aggressive web search of vulnerable pages: /images../.env /_nuxt/../.env /uploads../.env /api/.env / ...
show more
Aggressive web search of vulnerable pages: /images../.env /_nuxt/../.env /uploads../.env /api/.env /v1/.env ...
show less
Web App Attack
๐ช๐ธ
elcruzado.es
2026-08-29 01:19:04
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 136.110.116.228 (JP/Japan/228.116.110.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.110.116.228 (JP/Japan/228.116.110.136.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-29 00:58:41
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 136.110.116.228 (228.116.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 136.110.116.228 (228.116.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:58:37.695855 2026] [security2:error] [pid 9618:tid 9618] [client 136.110.116.228:8232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ohiobabe.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ohiobabe.com"] [uri "/@fs/root/.aws/credentials.bak"] [unique_id "apIuvZP30PmEj977HXgsvQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
sajmon0011
2026-08-29 00:38:48
(4 hours ago)
136.110.116.228 - - [29/Aug/2026:02:38:47 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 196 "-" "M ...
show more
136.110.116.228 - - [29/Aug/2026:02:38:47 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
...
show less
Web App Attack
๐ฉ๐ช
updown.io
2026-08-29 00:32:44
(4 hours ago)
{"level":"info","ts":1787963511.7519805,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1787963511.7519805,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.110.116.228","remote_port":"58646","client_ip":"136.110.116.228","proto":"HTTP/1.1","method":"GET","host":"waiverstatus.thinklumo.com","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:127.0) Gecko/20100101 Firefox/127.0"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000023555,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://waiverstatus.thinklumo.com/"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1787963518.7568152,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"136.110.116.228","remote_port":"3380","client_ip":"136.110.116.228","proto":"HTTP/1.1","method":"GET","host":"waiverstatus.thinklumo.com","uri":"/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??","headers":{"Accept-Encoding":["gzip"],"User-Agent":["
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:55:55
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:55:47.504763 2026] [security2:error] [pid 11171:tid 11171] [client 136.110.116.228:8800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mauriene.com"] [uri "/@fs/app/.env"] [unique_id "apIgA12URO0-rLJktWz70wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:16:52
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.110.116.228 (228.116.110.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:16:47.943296 2026] [security2:error] [pid 27163:tid 27163] [client 136.110.116.228:43916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.zmgmt.net"] [uri "/@fs/.env"] [unique_id "apIW36eMAq1kWmR-XoH0kAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-28 23:11:03
(5 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot