๐ง๐ท
Peregrine
2026-06-22 03:10:28
(6 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16: ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.env.example HTTP/1.1" 404 414
2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-21 13:04:11
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 09:04:04.724223 2026] [security2:error] [pid 13387:tid 13387] [client 2a06:a880:5:5e47::1:33432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brexitop.com"] [uri "/api/.env"] [unique_id "ajfhRPviR_ktoY-fh9_gngAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 12:44:25
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 08:44:21.021483 2026] [security2:error] [pid 24627:tid 24627] [client 2a06:a880:5:5e47::1:57998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "borzoi-color.batw.net"] [uri "/api/.env"] [unique_id "ajfcpQJWe1V9GAANTGVUVwAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-06-21 03:10:23
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16: ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.env.example HTTP/1.1" 404 414
2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-20 10:22:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 06:22:34.942803 2026] [security2:error] [pid 25576:tid 25576] [client 2a06:a880:5:5e47::1:36924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4lazy.com"] [uri "/api/.env"] [unique_id "ajZp6t-lOGJs_3YEbgUJhgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 09:39:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 05:39:23.478507 2026] [security2:error] [pid 29924:tid 29924] [client 2a06:a880:5:5e47::1:43302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marxistphilosophy.org"] [uri "/.env"] [unique_id "ajZfy-kazFxaIwdRTIhH-wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-20 05:41:50
(2 days ago)
2a06:a880:5:5e47::1 - - [20/Jun/2026:08:41:44 +0300] "GET /.env HTTP/1.1" 404 715 "-" "Mozilla/5.0 ( ...
show more
2a06:a880:5:5e47::1 - - [20/Jun/2026:08:41:44 +0300] "GET /.env HTTP/1.1" 404 715 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
2a06:a880:5:5e47::1 - - [20/Jun/2026:08:41:46 +0300] "GET /api/.env HTTP/1.1" 404 767 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 05:14:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 01:14:46.462661 2026] [security2:error] [pid 1396:tid 1416] [client 2a06:a880:5:5e47::1:33898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "officialseniorworldgolfranking.com"] [uri "/.env.example"] [unique_id "ajYhxsi3d1sVwh6vusxFNAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-06-20 03:45:22
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-20 03:26:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 23:26:05.788945 2026] [security2:error] [pid 10577:tid 10577] [client 2a06:a880:5:5e47::1:48460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stationrestaurant.ca"] [uri "/.env.example"] [unique_id "ajYITUlmt03IH7Z3ctvI0wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-06-20 02:37:00
(2 days ago)
IPBlock protected site ID [669-fx].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-06-20 02:16:15
(2 days ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16: ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.env.example HTTP/1.1" 404 414
2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
2a06:a880:5:5e47::1 172.71.98.223 - - [19/Jun/2026:23:16:05 -0300] "GET /.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-20 01:54:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 21:54:08.398724 2026] [security2:error] [pid 18304:tid 18304] [client 2a06:a880:5:5e47::1:49364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bmbb1.com"] [uri "/.env.example"] [unique_id "ajXywDZsPaoJ43QyOW4rDAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-06-19 23:57:52
(2 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 21:04:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:a880:5:5e47::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 17:04:31.937649 2026] [security2:error] [pid 17714:tid 17714] [client 2a06:a880:5:5e47::1:60708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.creartest.com"] [uri "/api/.env"] [unique_id "ajWu32BOgWLSu_BWP2VdQQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack