🇩🇪
iNetWorker
2026-09-04 14:11:56
(19 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:06:10
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:06.429929 2026] [security2:error] [pid 13794:tid 13794] [client 34.106.134.72:33712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jemsfood.com"] [uri "/.env"] [unique_id "aprQTpDWGeD6k-OmJ8ESmAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:04:10
(20 hours ago)
34.106.134.72 - - [04/Sep/2026:13:04:10 +0000] "GET /.env.bak HTTP/1.1" 404 7039 "-" "crusader-worke ...
show more
34.106.134.72 - - [04/Sep/2026:13:04:10 +0000] "GET /.env.bak HTTP/1.1" 404 7039 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 12:14:04
(21 hours ago)
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4440 "-" "crusa ...
show more
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4440 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4441 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /.env.dev HTTP/1.1" 404 4440 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /.env.example HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /actuator/configprops HTTP/1.1" 404 4441 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /crusader-404-probe HTTP/1.1" 404 4440 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /.env.old HTTP/1.1" 404 4441 "-" "crusader-worker/1.0"
34.106.134.72 - - [04/Sep/2026:14:14:02 +0200] "GET /env HTTP/1.1" 404 4440 "-" "crusad
show less
Web App Attack
Brute-Force
Anonymous
2026-09-04 11:30:02
(22 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:24:40
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:24:32.887902 2026] [security2:error] [pid 27369:tid 27369] [client 34.106.134.72:43734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evtoy.danged.com"] [uri "/wp-config.php.swp"] [unique_id "apqqcOdO--aeTt3b-OkMogAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
a.mohamed.go
2026-09-04 11:03:04
(22 hours ago)
Sep 04 13:03:04 sogod [435]: 34.106.134.72 "GET /actuator/env HTTP/1.0" 200 2606/0 0.003 - - 0 - 12
...
show more
Sep 04 13:03:04 sogod [435]: 34.106.134.72 "GET /actuator/env HTTP/1.0" 200 2606/0 0.003 - - 0 - 12
Sep 04 13:03:04 sogod [435]: 34.106.134.72 "GET /actuator/configprops HTTP/1.0" 200 2606/0 0.002 - - 0 - 12
Sep 04 13:03:04 sogod [435]: 34.106.134.72 "GET /_ignition/health-check HTTP/1.0" 200 2606/0 0.002 - - 0 - 12
...
show less
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-04 10:35:11
(23 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 09:18:14
(1 day ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 09:12:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.en ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.example HTTP/1.1
show less
Hacking
Web App Attack
🇨🇭
zynex
2026-09-04 08:29:18
(1 day ago)
URL Probing: /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:12:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:11:58.849967 2026] [security2:error] [pid 23004:tid 23111] [client 34.106.134.72:58576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreammile.info"] [uri "/wp-config.php~"] [unique_id "app9Ts4Kl8MzvCwEZxJkkgAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:45:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:45:44.031564 2026] [security2:error] [pid 2895:tid 2895] [client 34.106.134.72:36476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "getitenglish.casademunt.com"] [uri "/.env.old"] [unique_id "app3KAeQMIaSlmzv0DRBkwAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 07:25:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:18:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.134.72 (72.134.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:18:44.086625 2026] [security2:error] [pid 21651:tid 21651] [client 34.106.134.72:59164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daretownkindling.resilientigm.com"] [uri "/.env"] [unique_id "appw1CDrdXEubUb1Sk5XdwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack