🇺🇸
xxkodedxx
2026-09-06 06:37:04
(1 hour ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 23× edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 23× edge-block in 10m window.
Origin: US / AS396982 Google LLC
Active: 06:36:16 UTC
Volume: 23 HTTP req, 15 honeypot probe(s)
Bait taken: /.env.bak, /wp-config.php.bak, /actuator/env, /.env, /.env.backup
Status mix: 444×23
Vhost fishing: ip67-217-240-72.pbiaas.com
UA: "crusader-worker/1.0"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:49:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:49:24.414246 2026] [security2:error] [pid 243864:tid 243886] [client 136.70.71.34:42632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.coloradocritterpics.com"] [uri "/.env.example"] [unique_id "apzixBoMv5vcrl78L_RajgAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:32:11
(4 hours ago)
2026-09-06T05:32:09.960212+02:00 136.70.71.34:55566 http-in~ http-in/<NOSRV> 2/-1/-1/-1/2 410 961 - ...
show more
2026-09-06T05:32:09.960212+02:00 136.70.71.34:55566 http-in~ http-in/<NOSRV> 2/-1/-1/-1/2 410 961 - - PR-- 20/20/0/0/0 0/0 {chariot.pl} "GET /.env.old HTTP/1.1" WAF_ACTION:deny WAF_ID(s):920440,930130,949110
2026-09-06T05:32:09.961391+02:00 136.70.71.34:55590 http-in~ http-in/<NOSRV> 2/-1/-1/-1/2 410 961 - - PR-- 19/19/0/0/0 0/0 {chariot.pl} "GET /env HTTP/1.1" WAF_ACTION:- WAF_ID(s):-
2026-09-06T05:32:09.964751+02:00 136.70.71.34:55644 http-in~ http-in/<NOSRV> 5/-1/-1/-1/5 410 961 - - PR-- 18/18/0/0/0 0/0 {chariot.pl} "GET /.env.prod HTTP/1.1" WAF_ACTION:deny WAF_ID(s):930130,949110
2026-09-06T05:32:09.964899+02:00 136.70.71.34:55624 http-in~ http-in/<NOSRV> 4/-1/-1/-1/4 410 961 - - PR-- 17/17/0/0/0 0/0 {chariot.pl} "GET /.env HTTP/1.1" WAF_ACTION:deny WAF_ID(s):930130,949110
2026-09-06T05:32:09.965224+02:00 136.70.71.34:55594 http-in~ http-in/<NOSRV> 4/-1/-1/-1/4 410 961 - - PR-- 16/16/0/0/0 0/0 {chariot.pl} "GET /wp-config.php~ HTTP/1.1" WAF_ACTION:deny WAF_ID(s):920500,930130,94911
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:09.319357 2026] [security2:error] [pid 31929:tid 31929] [client 136.70.71.34:45326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.manatawnycreekfarm.com"] [uri "/.env.example"] [unique_id "apzWwd9ksQDea8Xn1xCKMAAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:30:05
(5 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 02:18:41
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:18:35.605302 2026] [security2:error] [pid 32304:tid 32304] [client 136.70.71.34:43444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.flightclaimservices.com"] [uri "/.env.local"] [unique_id "apzNe8dgElDQfEXyeRN45QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-06 01:31:42
(6 hours ago)
Wordpress login attempts
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 01:16:36
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:16:32.526271 2026] [security2:error] [pid 32538:tid 32538] [client 136.70.71.34:44256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sunshinenv.com"] [uri "/.env.prod"] [unique_id "apy-8CpqEmSGSuyskdNa_QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 01:05:50
(7 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇩🇪
Skyrider
2026-09-06 00:53:59
(7 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 00:51:23
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:22:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.70.71.34 (34.71.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:22:32.674126 2026] [security2:error] [pid 7979:tid 7979] [client 136.70.71.34:35532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "klingandi.com"] [uri "/.env.local"] [unique_id "apyySLrrV1BV7F6rHlRrLgAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 00:19:43
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇩🇪
Philister11
2026-09-06 00:03:57
(8 hours ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
🇩🇪
Dominik Lysiak
2026-09-05 23:54:32
(8 hours ago)
136.70.71.34 - - [06/Sep/2026:01:54:32 +0200] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worker ...
show more
136.70.71.34 - - [06/Sep/2026:01:54:32 +0200] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
136.70.71.34 - - [06/Sep/2026:01:54:32 +0200] "GET /.env.example HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
136.70.71.34 - - [06/Sep/2026:01:54:32 +0200] "GET /.env.production HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack