🇨🇭
GAS
2026-09-06 06:37:59
(10 hours ago)
Bad Bot.
34.22.63.240 - - [06/Sep/2026:08:37:58 +0200] "GET /.env.production HTTP/1.1" 402 4829 "-" ...
show more
Bad Bot.
34.22.63.240 - - [06/Sep/2026:08:37:58 +0200] "GET /.env.production HTTP/1.1" 402 4829 "-" "crusader-worker/1.0" "REDACTED" ""
...
show less
Bad Web Bot
Web App Attack
🇫🇷
LRNP
2026-09-06 06:30:33
(10 hours ago)
_:443 34.22.63.240 - - [06/Sep/2026:06:30:29 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worke ...
show more
_:443 34.22.63.240 - - [06/Sep/2026:06:30:29 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 06:28:55
(10 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 06:08:27
(11 hours ago)
34.22.63.240 - - [06/Sep/2026:03:08:26 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 1807 "-" "crusad ...
show more
34.22.63.240 - - [06/Sep/2026:03:08:26 -0300] "GET /wp-config.php.bak HTTP/1.1" 404 1807 "-" "crusader-worker/1.0"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
🇺🇸
TPI-Abuse
2026-09-06 03:54:45
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:36.352252 2026] [security2:error] [pid 3717596:tid 3717596] [client 34.22.63.240:57158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gwenwaltersartrep.com"] [uri "/.env.local"] [unique_id "apzj_PFDwaYKgsZ4ZjwYGQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:25:49
(14 hours ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /.env.bak
Web App Attack
🇺🇸
mnsf
2026-09-06 03:05:18
(14 hours ago)
Abuse Detected (3)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:02:05
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:01:58.654552 2026] [security2:error] [pid 20499:tid 20499] [client 34.22.63.240:36544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.stkm.com"] [uri "/.env.example"] [unique_id "apzXpqAYccbr4-WHXTCSvgAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 02:39:14
(14 hours ago)
Domain : uktt.info
Rule : hack
2026-09-06 02:37:15 ***hidden-privacy*** GET /wp-config.php.bak - 443 ...
show more
Domain : uktt.info
Rule : hack
2026-09-06 02:37:15 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 34.22.63.240 HTTP/1.1 crusader-worker/1.0 - uktt.info 404 0 2 1401 98 121 - -
show less
Hacking
SQL Injection
Brute-Force
🇩🇪
Vegascosmetics
2026-09-06 01:33:26
(15 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-config\.php (Match: /wp-config.php)
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:12:49
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:12:42.764128 2026] [security2:error] [pid 4939:tid 4939] [client 34.22.63.240:53912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.itaxcenter.com"] [uri "/.htaccess"] [unique_id "apy-CmFp0IjMcMs9DS2zqQAAAGI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
tsZero
2026-09-06 00:30:19
(16 hours ago)
Scan example: path=/actuator/env status=403
Hacking
🇳🇱
e.fierstra
2026-09-06 00:16:06
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-06 00:00:17
(17 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:55:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.63.240 (240.63.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:55:34.566671 2026] [security2:error] [pid 25265:tid 25265] [client 34.22.63.240:38888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aviil.net"] [uri "/.env.save"] [unique_id "apyr9qIdw9veVz7ssRz42QAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack