🇫🇷
bazter.pro
2026-09-06 07:07:00
(16 hours ago)
Auto-Ban [2026-09-06 10:07:00]: CRITICAL: .env attack; DC: Google LLC [Paths: 19] | Details: Exploit ...
show more
Auto-Ban [2026-09-06 10:07:00]: CRITICAL: .env attack; DC: Google LLC [Paths: 19] | Details: Exploit trap paths: /.env.save, /.env.old, /.env.bak, /.env.backup, /.env | Sensitive files/paths: /.env.save, /.env.old, /.env.bak, /.env.backup, /.env | 404 errors (19): /wp-config.php.swp, /.env.local, /.env.save, /.env.old, /.env.example, /env, /_ignition/health-check, /.env.production, /storage/logs/laravel.log, /.env.backup (and 9 more)
show less
Web App Attack
Hacking
🇧🇾
lns.bz
2026-09-06 06:29:39
(16 hours ago)
.env scanning [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:51:06
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:58.373484 2026] [security2:error] [pid 3717854:tid 3717854] [client 35.247.171.18:32980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nuegrapes.com"] [uri "/.env.local"] [unique_id "apzjIpVdsl6VRI3ERf_giwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 03:05:50
(20 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:56:04
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:55:56.991506 2026] [security2:error] [pid 27401:tid 27401] [client 35.247.171.18:55020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "outlet.kemela.com"] [uri "/.env"] [unique_id "apzWPJXC60wdbRyukUwmKQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-06 02:36:41
(20 hours ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:33:11
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:33:03.913803 2026] [security2:error] [pid 24013:tid 24013] [client 35.247.171.18:37920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fingerprintinternational.com"] [uri "/.env.local"] [unique_id "apzQ35e1AIHjeNWyoaL3bwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-06 01:54:57
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (SG/Singapore/18.171.247.35.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (SG/Singapore/18.171.247.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:40:26
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.171.18 (18.171.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.171.18 (18.171.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:40:21.560632 2026] [security2:error] [pid 3398:tid 3398] [client 35.247.171.18:33200] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||athenaanderson.andrsn.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "athenaanderson.andrsn.com"] [uri "/backup.sql"] [unique_id "apzEhfD3EejxrBj4R1IweAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 01:01:25
(22 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-06 00:33:36
(22 hours ago)
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | /.env ...
show more
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | /.env.production | /.env
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:00:13
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:00:00.602463 2026] [security2:error] [pid 29675:tid 29675] [client 35.247.171.18:53568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeremyurbanski.buffaloweddingdeejay.com"] [uri "/.env.dev"] [unique_id "apytAOzqzPuJWd6udslZ4gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:53:43
(23 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.247.171.18 (SG/Singapore/18.171.247.35.bc ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.247.171.18 (SG/Singapore/18.171.247.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.247.171.18 - - [06/Sep/2026:01:53:40 +0200] "GET /.env.old HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
35.247.171.18 - - [06/Sep/2026:01:53:40 +0200] "GET /.env.bak HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
35.247.171.18 - - [06/Sep/2026:01:53:40 +0200] "GET /.env.save HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan
🇬🇧
Aetherweb Ark
2026-09-05 23:48:57
(23 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.247.171.18 (SG/Singapore/18.171.247.35.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 35.247.171.18 (SG/Singapore/18.171.247.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:53:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.171.18 (18.171.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:53:41.639896 2026] [security2:error] [pid 13023:tid 13023] [client 35.247.171.18:42490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.creeation.com"] [uri "/wp-config.php~"] [unique_id "apyddWKz5t29r8sfoE1oYgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack