๐ง๐ช
sid3windr
2026-08-27 18:23:45
(6 minutes ago)
GET /.env (Tarpitted for 4m20s, wasted 15.35kB)
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 17:44:24
(45 minutes ago)
Multiple WAF Violations
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-27 17:27:49
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-08-27 16:05:04
(2 hours ago)
blocked for webapp attack | path requested: /.env | seen at 2026-08-27 16:04:40.938 |
Web App Attack
๐ซ๐ท
pm33
2026-08-27 15:13:31
(3 hours ago)
Excessive crawling HTTP 404
Web App Attack
Anonymous
2026-08-27 15:07:49
(3 hours ago)
34.175.53.0 - - [27/Aug/2026:15:07:48 +0000] "GET /.env.local HTTP/1.1" 404 21278 "-" "crusader-work ...
show more
34.175.53.0 - - [27/Aug/2026:15:07:48 +0000] "GET /.env.local HTTP/1.1" 404 21278 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:28:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:28:36.450628 2026] [security2:error] [pid 1875:tid 1875] [client 34.175.53.0:39960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.funkita.chevronparkett.com"] [uri "/.env.old"] [unique_id "apBJlA7eOzW3w_d2QyTWiAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:16:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:16:29.985345 2026] [security2:error] [pid 19764:tid 19764] [client 34.175.53.0:35912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hierrosbernal.ayudaclic.com"] [uri "/.env.save"] [unique_id "apA4rbIC1XTPmmeOEYHBgQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:56:05
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:55:59.511944 2026] [security2:error] [pid 20884:tid 20884] [client 34.175.53.0:46752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thespotfurniture.trademartghana.com"] [uri "/wp-config.php.swp"] [unique_id "apAz3-qPELjycb8XOooyxAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-27 11:55:24
(6 hours ago)
[27/Aug/2026:14:55:24 +0300] -- 34.175.53.0 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.s ...
show more
[27/Aug/2026:14:55:24 +0300] -- 34.175.53.0 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 11:37:11
(6 hours ago)
Http Port:80 (http_status:403) - Agent:crusader-worker/1.0
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:31:50
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.53.0 (0.53.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:31:46.089712 2026] [security2:error] [pid 28156:tid 28156] [client 34.175.53.0:33780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.penisbreath.com.whoore.com"] [uri "/.env.save"] [unique_id "apAgIiLP2MnkkxwoJiFbtwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-08-27 11:27:39
(7 hours ago)
WebAttack or semilar from 34.175.53.0
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 11:24:34
(7 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-27 11:09:52
(7 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-14)
Hacking
Bad Web Bot