🇺🇸
TPI-Abuse
2026-09-06 03:50:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:33.348444 2026] [security2:error] [pid 27944:tid 27944] [client 34.80.243.235:58124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kalvannastudios.com"] [uri "/.env.production"] [unique_id "apzjCWhqy6ksuA2cNFMrNgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-06 03:29:36
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:39:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:39:48.649016 2026] [security2:error] [pid 16626:tid 16674] [client 34.80.243.235:58070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imap.absurdotron.com"] [uri "/.env.backup"] [unique_id "apzSdLJA6db0_H1oeKYtCAAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-06 02:39:11
(2 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-06 02:04:48
(3 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
🇮🇩
penjaga BRIN
2026-09-06 00:51:33
(4 hours ago)
Suspicious malicious activity
Hacking
🇳🇱
e.fierstra
2026-09-06 00:19:36
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(5 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-05 23:54:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:45.281075 2026] [security2:error] [pid 7595:tid 7595] [client 34.80.243.235:35608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cartoondelivery.com"] [uri "/.env"] [unique_id "apyrxSKT-7KBAYJgjsKLpAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:56:36
(6 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.80.243.235 (TW/Taiwan/235.243.80.34.bc.go ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.80.243.235 (TW/Taiwan/235.243.80.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.80.243.235 - - [06/Sep/2026:00:56:31 +0200] "GET /.env.example HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:00:56:31 +0200] "GET /.env.save HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:00:56:31 +0200] "GET /.env.old HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
🇩🇪
4server
2026-09-05 22:38:53
(6 hours ago)
[SunSep0600:38:47.9752802026][security2:error][pid2094347:tid2094400][client34.80.243.235:0]ModSecur ...
show more
[SunSep0600:38:47.9752802026][security2:error][pid2094347:tid2094400][client34.80.243.235:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"glass-container.com\"][uri\"/.env.example\"][unique_id\"apyZ92raS7iCyMc0ZoB5wAAAAYo\"]
show less
Port Scan
Brute-Force
Web App Attack
🇩🇪
NihiliousMonk
2026-09-05 22:26:34
(6 hours ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:40:31
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.243.235 (235.243.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:40:22.223551 2026] [security2:error] [pid 26982:tid 26982] [client 34.80.243.235:58248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ahuramazda.com"] [uri "/.env"] [unique_id "apyMRpI-NAGHnLQP6J4MnQAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
on-com
2026-09-05 21:37:39
(7 hours ago)
URL scan
Brute-Force
Web App Attack
🇦🇺
electronico
2026-09-05 21:31:59
(7 hours ago)
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /.env.production HTTP/1.1" 404 7418 "-" "crusade ...
show more
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /.env.production HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /crusader-404-probe HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /.env.prod HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /wp-config.php.bak HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /wp-config.php~ HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /env HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /_ignition/health-check HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /.env.backup HTTP/1.1" 404 7418 "-" "crusader-worker/1.0"
34.80.243.235 - - [06/Sep/2026:08:31:58 +1100] "GET /.env.save HTTP/1.1" 404 7418 "-" "crusader-wor
...
show less
Brute-Force
Web App Attack