Anonymous
2026-09-21 07:26:47
(1 day ago)
35.247.135.11 - - [20/Sep/2026:16:15:51 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Ma ...
show more
35.247.135.11 - - [20/Sep/2026:16:15:51 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" 35.247.135.11
35.247.135.11 - - [20/Sep/2026:16:15:51 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 35.247.135.11
35.247.135.11 - - [20/Sep/2026:16:15:52 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 35.247.135.11
35.247.135.11 - - [20/Sep/2026:16:15:52 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 35.247.135.11
35.247.135.11 - - [20/Sep/2026:16:15:53 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +cla
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 06:21:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 02:21:49.682612 2026] [security2:error] [pid 11529:tid 11529] [client 35.247.135.11:56082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.recetabook.com"] [uri "/@fs/app/.env"] [unique_id "arDM_dQjDWBAFN_L6iJdjAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:46:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:46:48.292891 2026] [security2:error] [pid 24685:tid 24685] [client 35.247.135.11:45922] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rememberingemily.com.pswebsite.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rememberingemily.com.pswebsite.com"] [uri "/server.key"] [unique_id "arDEyFFyP4aHffxaSwcIGQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-09-21 05:46:44
(1 day ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:39:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:39:21.950055 2026] [security2:error] [pid 11191:tid 11191] [client 35.247.135.11:50252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ratalads.com"] [uri "/@fs/src/.env"] [unique_id "arC0-WfwDQyd8oTcMLGFxAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:46:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:46:09.334205 2026] [security2:error] [pid 5572:tid 5572] [client 35.247.135.11:51318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikeneame.com"] [uri "/.env.production"] [unique_id "arCogeEK2Y1yjCkCN2ai7QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:26:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:26:45.874983 2026] [security2:error] [pid 20767:tid 20767] [client 35.247.135.11:41138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proyectando.com"] [uri "/@fs/../.env"] [unique_id "arCj9QBmDJ8K9-78pHyXmQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 03:05:26
(1 day ago)
Too many Status 40X (24)
Brute-Force
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-21 02:36:58
(1 day ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 1s
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 02:18:20
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot
๐บ๐ธ
IndigoRidge
2026-09-21 02:17:56
(1 day ago)
35.247.135.11 - - [20/Sep/2026:22:17:55 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 42547 "-" "Moz ...
show more
35.247.135.11 - - [20/Sep/2026:22:17:55 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 42547 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.247.135.11 - - [20/Sep/2026:22:17:55 -0400] "GET /@fs/../.env?raw?? HTTP/1.1" 404 42547 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.247.135.11 - - [20/Sep/2026:22:17:55 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 42547 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 01:28:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 21:28:21.796705 2026] [security2:error] [pid 4569:tid 4676] [client 35.247.135.11:60650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.reattaforsale.com"] [uri "/.git/config"] [unique_id "arCINeuMUIqg_C22PH2GIAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:36:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:36:02.692344 2026] [security2:error] [pid 30445:tid 30445] [client 35.247.135.11:41502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nathanburd.com|F|2"] [data ".nathanburd.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nathanburd.com"] [uri "/z9x8c7v6b5-debug-trigger-www.nathanburd.com"] [unique_id "arBt4txFjsr5WynjjRimegAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 23:20:31
(1 day ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-20 23:20 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 23:08:09
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.247.135.11 (11.135.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.135.11 (11.135.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:07:57.637468 2026] [security2:error] [pid 4087:tid 4087] [client 35.247.135.11:59174] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.refreshmc.com|F|2"] [data ".refreshmc.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.refreshmc.com"] [uri "/z9x8c7v6b5-debug-trigger-www.refreshmc.com"] [unique_id "arBnTQWNN_2cR60iQUGsoAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack