🇩🇪
FD-IX
2026-09-04 14:55:45
(13 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-04 14:39:49
(13 hours ago)
URL Probing: /.env
Web App Attack
Anonymous
2026-09-04 14:36:36
(13 hours ago)
fail2ban: apache-auth jail (3 hits in 2419200s) on skipper
Brute-Force
Web App Attack
Anonymous
2026-09-04 13:40:31
(14 hours ago)
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /.env HTTP/1.1
Hacking
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 13:27:03
(15 hours ago)
[04/Sep/2026:16:27:03 +0300] -- 34.186.47.64 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env. ...
show more
[04/Sep/2026:16:27:03 +0300] -- 34.186.47.64 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.backup HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:53:56
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:53:50.293099 2026] [security2:error] [pid 14119:tid 14119] [client 34.186.47.64:51638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marketfuel.co"] [uri "/.env.dev"] [unique_id "apq_XgWLoPZI2FIRA1HPowAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:40:21
(15 hours ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:45:43
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:37.909399 2026] [security2:error] [pid 4061:tid 4061] [client 34.186.47.64:36908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.saratogaequity.com"] [uri "/.env.production"] [unique_id "apqvYY9Xxv6MYqSUVOrN3wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:08:05
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:08:01.005005 2026] [security2:error] [pid 18659:tid 18659] [client 34.186.47.64:43794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpastorphotographics.com"] [uri "/wp-config.php~"] [unique_id "apqYgc2IUApT2w9JGCbtaAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 10:06:09
(18 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-04 08:29:43
(19 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.186.47.64 (US/United States/64.47.186.34. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.186.47.64 (US/United States/64.47.186.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.186.47.64 - - [04/Sep/2026:10:29:41 +0200] "GET /.env.local HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:29:41 +0200] "GET /.env.bak HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:29:41 +0200] "GET /.env.dev HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
Anonymous
2026-09-04 08:25:28
(20 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:15:30
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:15:22.727788 2026] [security2:error] [pid 2442125:tid 2442270] [client 34.186.47.64:38620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drronaldhecker.com"] [uri "/.env.dev"] [unique_id "app-GiUHlBTk_P9VBNzfYQAAApI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 08:00:14
(20 hours ago)
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4494 "-" "crusader- ...
show more
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4494 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /actuator/configprops HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /.env.old HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /env HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /.env HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4494 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /.env.local HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.186.47.64 - - [04/Sep/2026:10:00:10 +0200] "GET /.env.example HTTP/1.1" 404 4495 "-" "crusader-worker/1.0"
34.186.4
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 07:03:43
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.47.64 (64.47.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:03:35.602803 2026] [security2:error] [pid 151887:tid 151887] [client 34.186.47.64:37978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbreen.nancybcatering.com"] [uri "/.env.prod"] [unique_id "apptR7DyLeWbjYHYQMeTOgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack