Anonymous
2026-10-09 04:35:41
(23 minutes ago)
8.235.99.15 - - [08/Oct/2026:23:35:35 -0500] "GET /.env HTTP/1.1" 403 199 "http://synapseresults.com ...
show more
8.235.99.15 - - [08/Oct/2026:23:35:35 -0500] "GET /.env HTTP/1.1" 403 199 "http://synapseresults.com/cache/original/%2e%2e/%2e%2e/.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 172.71.150.41
8.235.99.15 - - [08/Oct/2026:23:35:39 -0500] "GET /.env HTTP/1.1" 301 243 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 172.71.151.229
8.235.99.15 - - [08/Oct/2026:23:35:39 -0500] "GET /.env HTTP/1.1" 403 199 "http://synapseresults.com/.env" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 172.71.150.40
8.235.99.15 - - [08/Oct/2026:23:35:40 -0500] "GET /.env.example HTTP/1.1" 301 251 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 172.71.151.229
8.235.99.15 - - [08/Oct/2026:23:35:40 -0500] "GET /.env.production HTTP/1.1" 301 254 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 172.68.23.34
8.235.99.15 - - [08/Oct/2026:23:35:40 -0500] "GET /.env.bak HTTP/1.1" 301 247 "-" "Mozilla/5.
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-09 03:19:05
(1 hour ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.local [RATE LIMITED - 1800s quarantine] | Pays: US ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.local [RATE LIMITED - 1800s quarantine] | Pays: US | UA: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webma
show less
Hacking
Web App Attack
๐จ๐ฆ
zXero
2026-10-09 02:32:35
(2 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
๐ฉ๐ช
mravb
2026-10-09 02:10:07
(2 hours ago)
8.235.99.15 - - [09/Oct/2026:05:10:06 +0300] "GET /@fs/app/.env?raw?? HTTP/2.0" 444 0 "-" "Mozilla/5 ...
show more
8.235.99.15 - - [09/Oct/2026:05:10:06 +0300] "GET /@fs/app/.env?raw?? HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Hacking
๐จ๐ฆ
Mediashaker
2026-10-09 01:52:50
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 8.235.99.15 (US/Unit ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 8.235.99.15 (US/United States/15.99.235.8.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 01:37:43
(3 hours ago)
(mod_security) mod_security (id:210580) triggered by 8.235.99.15 (15.99.235.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 8.235.99.15 (15.99.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:37:36.361935 2026] [security2:error] [pid 14938:tid 15003] [client 8.235.99.15:54982] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||kandooo.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "kandooo.com"] [uri "/api/fs/read"] [unique_id "ashFYHu1BFHX9McVXCIq9QAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-10-09 01:33:37
(3 hours ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-10-09 01:30:04
(3 hours ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack
๐ฉ๐ช
Phenix Info
2026-10-09 01:12:31
(3 hours ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:10:46
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.235.99.15 (15.99.235.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 8.235.99.15 (15.99.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:10:41.205282 2026] [security2:error] [pid 17722:tid 17743] [client 8.235.99.15:59388] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||heworeblack.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "heworeblack.com"] [uri "/z9x8c7v6b5-debug-trigger-heworeblack.com"] [unique_id "asg_ER58bfpzP7WdpUsk_wAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
masterguru
2026-10-09 01:01:49
(3 hours ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-185)
show less
Hacking
๐ฉ๐ช
bazter.pro
2026-10-09 00:56:32
(4 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-09 00:29:55
(4 hours ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
yvoictra
2026-10-09 00:26:05
(4 hours ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:21:00
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.235.99.15 (15.99.235.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 8.235.99.15 (15.99.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:20:54.090043 2026] [security2:error] [pid 2578:tid 2578] [client 8.235.99.15:40912] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digitalmarketing-group.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digitalmarketing-group.com"] [uri "/z9x8c7v6b5-debug-trigger-digitalmarketing-group.com"] [unique_id "asgzZhMhIN2az7Tdh4qjSQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack