Anonymous
2026-08-01 01:11:39
(1 minute ago)
Attempted search for exploits and vulnerabilities detected by fail2ban
...
Port Scan
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-01 01:05:37
(7 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:05:32.267545 2026] [security2:error] [pid 1055781:tid 1055781] [client 136.65.221.0:47370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.onlinesuretybonds.com"] [uri "/.env.local"] [unique_id "am1GXFs-VfjWBoE6a4fyzgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-31 23:29:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:29:23.200398 2026] [security2:error] [pid 1390148:tid 1390148] [client 136.65.221.0:46168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bmillernotary.com"] [uri "/.env.development"] [unique_id "am0v0yVV4eKseBTQLEXeCgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-07-31 23:16:52
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π¬π§
Apache
2026-07-31 23:10:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (US/United States/0.221.65.136.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (US/United States/0.221.65.136.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
π«π·
masterguru
2026-07-31 23:10:34
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.65.221.0 (US/United States/0.221. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.65.221.0 (US/United States/0.221.65.136.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-07-31 23:09:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:09:45.401582 2026] [security2:error] [pid 3754191:tid 3754202] [client 136.65.221.0:64038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aapm.info"] [uri "/.env.staging"] [unique_id "am0rOZ-7BhzdtAVbmGKqhQAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³πΏ
Antinson
2026-07-31 23:02:13
(2 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
π΅π±
Budyn
2026-07-31 23:00:05
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: pma.budyn.ovh | URI: /.env | UA: CCBot/2.0 (https://commoncrawl.org/faq/) | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-07-31 22:50:53
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π©πͺ
SCHAPPY
2026-07-31 22:34:22
(2 hours ago)
Probing for non-installed web apps or current vulnerabilities.
Hacking
Web App Attack
πΊπΈ
kosada.com
2026-07-31 22:31:54
(2 hours ago)
Web vulnerability probing: /.env.bak
Web App Attack
π²πΎ
Rizzy
2026-07-31 22:28:34
(2 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-31 22:17:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:17:44.463410 2026] [security2:error] [pid 1222460:tid 1222460] [client 136.65.221.0:4476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.solutiongroove.com"] [uri "/.env"] [unique_id "am0fCP4hQ9W-Qx5-TxqkZwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-31 21:57:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.65.221.0 (0.221.65.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:57:36.102573 2026] [security2:error] [pid 306123:tid 306123] [client 136.65.221.0:60912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.uppermotradingco.com"] [uri "/.env.development"] [unique_id "am0aUJnMpyGwr_K-Feec9QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack