🇧🇬
Stoyko Stoykov
2026-09-06 06:38:51
(7 minutes ago)
34.10.159.215 - - [06/Sep/2026:09:38:50 +0300] "GET /.env HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
...
show more
34.10.159.215 - - [06/Sep/2026:09:38:50 +0300] "GET /.env HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-06 06:24:40
(21 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.10.159.215 (US/United States/215.159 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.10.159.215 (US/United States/215.159.10.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
ssssssssssssssssssssuper
2026-09-06 06:18:06
(28 minutes ago)
34.10.159.215 - - [06/Sep/2026:02:18:06 -0400] "GET /.env.prod HTTP/1.1" 404 65161 "-" "crusader-wor ...
show more
34.10.159.215 - - [06/Sep/2026:02:18:06 -0400] "GET /.env.prod HTTP/1.1" 404 65161 "-" "crusader-worker/1.0"
34.10.159.215 - - [06/Sep/2026:02:18:06 -0400] "GET /.env.production HTTP/1.1" 404 65161 "-" "crusader-worker/1.0"
34.10.159.215 - - [06/Sep/2026:02:18:06 -0400] "GET /.env HTTP/1.1" 404 65161 "-" "crusader-worker/1.0"
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:29.309463 2026] [security2:error] [pid 31595:tid 31595] [client 34.10.159.215:53032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.willyouanswerthecall.com"] [uri "/.env"] [unique_id "apzjfVRMB22mBv-neYwoFAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:27:33
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:27:26.152180 2026] [security2:error] [pid 11165:tid 11174] [client 34.10.159.215:40812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedprojectmanagement.com.aafm.us"] [uri "/.env.prod"] [unique_id "apzdnv1pRt8N7QnZBIkfXgAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-09-06 03:17:01
(3 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-06 03:02:31
(3 hours ago)
Blocked by ConnMonitor
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-06 02:22:47
(4 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
🇺🇸
mnsf
2026-09-06 02:05:13
(4 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-06 00:51:46
(5 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.eumedline.com; logs=/var/log/httpd/domains/eumedline.co ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.eumedline.com; logs=/var/log/httpd/domains/eumedline.com.log; samples=/.env.prod | /.env.save | /.env.backup
show less
Hacking
Web App Attack
🇩🇪
raph
2026-09-06 00:36:50
(6 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:28:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:28:09.074371 2026] [security2:error] [pid 5668:tid 5668] [client 34.10.159.215:44898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vvs-inc.com"] [uri "/wp-config.php.swp"] [unique_id "apyzmSt2unnlcXYBjJmWKQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 00:01:50
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:16
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.10.159.215 (215.159.10.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:08.704915 2026] [security2:error] [pid 16483:tid 16483] [client 34.10.159.215:36186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.the-practical-pionus.com"] [uri "/.env.local"] [unique_id "apyroLfv3cy8HNbV-XHDXwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:03:54
(7 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.10.159.215 (US/United States/215.159.10.3 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.10.159.215 (US/United States/215.159.10.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.10.159.215 - - [06/Sep/2026:01:03:53 +0200] "GET /.env.old HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.10.159.215 - - [06/Sep/2026:01:03:53 +0200] "GET /.env.production HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
34.10.159.215 - - [06/Sep/2026:01:03:53 +0200] "GET /.env.prod HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
show less
Port Scan