๐บ๐ธ
TPI-Abuse
2026-07-31 22:48:41
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:48:38.114486 2026] [security2:error] [pid 3134688:tid 3134688] [client 136.115.79.21:30708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.igpcloud.biz"] [uri "/.env"] [unique_id "am0mRg03irmi11e2eQ4e5QAAAGg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-31 22:40:16
(24 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 136.115.79.21 (US/United States/Iowa/Co ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.115.79.21 (US/United States/Iowa/Council Bluffs/21.79.115.136.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-31 22:31:39
(32 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:31:30.541191 2026] [security2:error] [pid 219448:tid 219448] [client 136.115.79.21:13832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.transcapitalsolutions.com"] [uri "/.env.local"] [unique_id "am0iQk6rIONtWOPe3p1qAAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-31 22:05:28
(59 minutes ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-07-31 22:05:09
(59 minutes ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 22:02:51
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:02:48.276201 2026] [security2:error] [pid 3226515:tid 3226515] [client 136.115.79.21:5966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.guardiancns.com"] [uri "/.env.development"] [unique_id "am0biD5BQm3Yr5qPs6ml-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-31 21:59:13
(1 hour ago)
Auto-ban: >3000 req/min op 2026-07-31
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 21:17:41
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:17:37.710390 2026] [security2:error] [pid 3895914:tid 3895914] [client 136.115.79.21:55654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pixelspective.com"] [uri "/.env.production"] [unique_id "am0Q8UHwoMkzOliNANrgoQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-31 21:12:41
(1 hour ago)
25 attempts against mh-misbehave-ban on plum
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
Evag Touf
2026-07-31 21:11:55
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 136.115.79.21 (US/United States/21.79.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 136.115.79.21 (US/United States/21.79.115.136.bc.googleusercontent.com)
show less
SQL Injection
๐ฒ๐พ
Rizzy
2026-07-31 21:04:34
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 20:56:19
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:56:11.417615 2026] [security2:error] [pid 16697:tid 16697] [client 136.115.79.21:3810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nautanet.info"] [uri "/.env.local"] [unique_id "am0L665M31FTIe6M9BvaAQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-07-31 20:54:09
(2 hours ago)
1.134 requests with url.path *.env
252 requests with url.path *credentials.json
173 requests with ...
show more
1.134 requests with url.path *.env
252 requests with url.path *credentials.json
173 requests with url.path *.aws/*
149 requests with url.path *config.php
143 requests with url.path *.azure/*
117 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
๐ธ๐ฎ
administrator
2026-07-31 20:51:39
(2 hours ago)
2026-07-31 22:51:38,750 fail2ban.actions [356575]: NOTICE [apache-badbots] Ban 136.115.79.21 ...
show more
2026-07-31 22:51:38,750 fail2ban.actions [356575]: NOTICE [apache-badbots] Ban 136.115.79.21
2026-07-31 22:51:38,967 fail2ban.actions [356575]: NOTICE [apache-auth] Ban 136.115.79.21
2026-07-31 22:51:38,970 fail2ban.actions [356575]: NOTICE [error-bots] Ban 136.115.79.21
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 20:40:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.79.21 (21.79.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:40:11.233472 2026] [security2:error] [pid 1219465:tid 1219465] [client 136.115.79.21:18072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dhsgrad.net"] [uri "/.env"] [unique_id "am0IK7Cf7_ROjfyHNoA6xAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack