๐บ๐ธ
entangled_mongoose
2026-09-01 08:44:13
(2 hours ago)
Probed /wp-config.php.swp.
Web App Attack
๐ฉ๐ช
maxpower
2026-09-01 08:28:33
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.101.162.133 (ID/Indonesia/133.162.101 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.101.162.133 (ID/Indonesia/133.162.101.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.101.162.133 - - [01/Sep/2026:10:28:30 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 146 "-" "crusader-worker/1.0" "-" host=mediaqualitylab.it
show less
Port Scan
๐ฒ๐พ
Rizzy
2026-09-01 07:37:10
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-01 07:11:51
(3 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 06:59:29
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-09-01 06:33:40
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-env-access.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:04:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.162.133 (133.162.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.162.133 (133.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:52.301529 2026] [security2:error] [pid 8404:tid 8404] [client 34.101.162.133:57028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.magodarman.com"] [uri "/.env.prod"] [unique_id "apZqyDXR3owi2-kXfr5WMgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:53:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.162.133 (133.162.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.162.133 (133.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:53:43.169692 2026] [security2:error] [pid 9700:tid 9775] [client 34.101.162.133:56810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aapmglobal.com"] [uri "/.env.bak"] [unique_id "apZaV5w9967_aSs1uS6ccgAAAc0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:47:45
(6 hours ago)
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /crusader-404-probe HTTP/1.1" 404 196 "-" "crus ...
show more
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /crusader-404-probe HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /.env.dev HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /.env.prod HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /actuator/env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /.env.bak HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /_ignition/health-check HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.101.162.133 - - [01/Sep/2026:12:47:45 +0800] "GET /wp-config.php.swp HTTP/1.1" 404 196 "-" "crus
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:58:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.162.133 (133.162.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.162.133 (133.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:58:02.414213 2026] [security2:error] [pid 21911:tid 21911] [client 34.101.162.133:50996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ladylilac.lilachost.net"] [uri "/wp-config.php~"] [unique_id "apZNSmGGE_87gClflvtRLwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-01 03:50:05
(7 hours ago)
34.101.162.133 - - [01/Sep/2026:09:20:04 +0530] "GET /actuator/env HTTP/1.1" 404 146 "-" "crusader-w ...
show more
34.101.162.133 - - [01/Sep/2026:09:20:04 +0530] "GET /actuator/env HTTP/1.1" 404 146 "-" "crusader-worker/1.0" "-"
show less
Web App Attack
๐ซ๐ฎ
YF
2026-09-01 03:31:10
(7 hours ago)
WordPress config file probe
Web App Attack
๐ฌ๐ง
gigatech
2026-09-01 03:05:03
(7 hours ago)
Webserver Probing
Web App Attack
๐ฉ๐ช
jeannelboutique
2026-09-01 02:47:55
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.101.162.133 (ID/Indonesia/133.162.10 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.101.162.133 (ID/Indonesia/133.162.101.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
CBJ
2026-09-01 02:42:56
(8 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack