Anonymous
2026-09-01 11:10:35
(2 hours ago)
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /.env.example HTTP/1.1" 404 196 "-" "crusader-wo ...
show more
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /.env.example HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /wp-config.php~ HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /crusader-404-probe HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /actuator/env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /storage/logs/laravel.log HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /wp-config.php.bak HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.106.12.222 - - [01/Sep/2026:19:10:34 +0800] "GET /.env.old HTTP/1.1" 404 196 "-" "crusader-worker/
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:07:07
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:07:01.980265 2026] [security2:error] [pid 12667:tid 12667] [client 34.106.12.222:44752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.edelbaumarchitect.com"] [uri "/.env.backup"] [unique_id "apax1f87dv9ILLB4zGLQ6AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:18:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:18:44.320326 2026] [security2:error] [pid 20084:tid 20130] [client 34.106.12.222:48240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afghanistantraveller.com"] [uri "/.env.example"] [unique_id "apamhOlg42CGBgLAd2Wq6QAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-01 10:13:45
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-01 09:21:30
(3 hours ago)
[ns67.kdns.gr] httpd-config-scan: sites=stage.troupakisaccounting.gr,ipv4.stage.troupakisaccounting. ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=stage.troupakisaccounting.gr,ipv4.stage.troupakisaccounting.gr; logs=/var/www/vhosts/system/stage.troupakisaccounting.gr/logs/access_ssl_log,/var/www/vhosts/system/stage.troupakisaccounting.gr/logs/proxy_access_ssl_log; samples=/.env | /.env.save | /.env.dev
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:18:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:18:29.575665 2026] [security2:error] [pid 1906:tid 1906] [client 34.106.12.222:36788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "au.tonylai.com"] [uri "/.env.backup"] [unique_id "apaKVTNcjic5EjNCXqfzpwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2026-09-01 07:15:36
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
πΊπΈ
mnsf
2026-09-01 07:05:38
(6 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
π¬π§
pinguin
2026-09-01 06:30:57
(6 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php~
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-01 05:08:06
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:08:01.761647 2026] [security2:error] [pid 5530:tid 5530] [client 34.106.12.222:46454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.novobeads.com"] [uri "/wp-config.php.bak"] [unique_id "apZdsZwVLMscAxPTbgn8zgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
zynex
2026-09-01 03:42:32
(9 hours ago)
URL Probing: /.env
Web App Attack
π³π΄
jad-abuse
2026-09-01 02:47:50
(10 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, config_backup, ignition_debug, actuator. Observed by 1 sensor(s); 43 hits.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 02:40:44
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.12.222 (222.12.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:40:40.673311 2026] [security2:error] [pid 30013:tid 30013] [client 34.106.12.222:59098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.debzy.com"] [uri "/.env.prod"] [unique_id "apY7KCEGSk4LkNtJ0itc0AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-09-01 02:36:47
(10 hours ago)
Multiple WAF Violations
Web App Attack
π·πΊ
DZBOT
2026-09-01 02:30:05
(10 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack