๐ซ๐ท
LRNP
2026-08-01 16:17:21
(56 seconds ago)
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env.production HTTP/1 ...
show more
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env.production HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env.backup HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env.dev HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env.bak HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env.old HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
experiments.lpoujol.fr:443 8.231.97.13 - - [01/Aug/2026:16:17:20 +0000] "GET
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
myintarweb
2026-08-01 15:50:18
(27 minutes ago)
8.231.97.13 - - [01/Aug/2026:16:50:17 +0100] 80 "GET /.env HTTP/1.1" 410 1504 "-" "crusader-worker/1 ...
show more
8.231.97.13 - - [01/Aug/2026:16:50:17 +0100] 80 "GET /.env HTTP/1.1" 410 1504 "-" "crusader-worker/1.0"
8.231.97.13 - - [01/Aug/2026:16:50:17 +0100] 80 "GET /.env.old HTTP/1.1" 410 1504 "-" "crusader-worker/1.0"
8.231.97.13 - - [01/Aug/2026:16:50:17 +0100] 80 "GET /.env.bak HTTP/1.1" 410 1504 "-" "crusader-worker/1.0"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:32:54
(45 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:32:50.241272 2026] [security2:error] [pid 2419212:tid 2419212] [client 8.231.97.13:59946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goochcompanies.com"] [uri "/.env"] [unique_id "am4RomnyOpJIQo0yJlfBXQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:49:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:49:12.819201 2026] [security2:error] [pid 2644183:tid 2644183] [client 8.231.97.13:45670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidnevueconcerts.com"] [uri "/.env.example"] [unique_id "am4HaP9tJfcuJSCgHxtciQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 14:29:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:29:27.792108 2026] [security2:error] [pid 2015823:tid 2015823] [client 8.231.97.13:57906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idahostem.org"] [uri "/.env.old"] [unique_id "am4Cx7h68njxUU_jYqrzhwAAAF4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 14:17:32
(2 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.dev | 5 distinct paths | UA: crusader-work ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.dev | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ฌ๐ง
consul.to
2026-08-01 13:53:53
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:52:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:52:40.470440 2026] [security2:error] [pid 4177945:tid 4177945] [client 8.231.97.13:53720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cydab.com"] [uri "/.env.example"] [unique_id "am36KNjN4L0JPDANzsww1gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-08-01 13:45:02
(2 hours ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ต๐ฑ
Budyn
2026-08-01 13:39:35
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: node-pl.budyn.ovh | URI: /.env.production | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-08-01 13:28:05
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.ex ...
show more
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:16:29
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:16:24.989493 2026] [security2:error] [pid 3940988:tid 3940988] [client 8.231.97.13:55096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stepiz62.com.appsdips.com"] [uri "/.env.prod"] [unique_id "am3xqP6KSzAKZVOVLIdK-wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 13:13:09
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 12:55:33
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.97.13 (13.97.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:55:27.037223 2026] [security2:error] [pid 2645190:tid 2645190] [client 8.231.97.13:42778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sublimationconsultants.ipostsocialmedia.com"] [uri "/.env.production"] [unique_id "am3sv6M7Aq2JWh8Le9TVqgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 12:50:04
(3 hours ago)
suspicious request in access.log
Web App Attack