๐ฉ๐ช
Dominik Lysiak
2026-09-01 05:03:12
(52 minutes ago)
34.12.132.25 - - [01/Sep/2026:07:03:11 +0200] "GET /.env.old HTTP/1.1" 404 319 "-" "crusader-worker/ ...
show more
34.12.132.25 - - [01/Sep/2026:07:03:11 +0200] "GET /.env.old HTTP/1.1" 404 319 "-" "crusader-worker/1.0"
34.12.132.25 - - [01/Sep/2026:07:03:11 +0200] "GET /.env.bak HTTP/1.1" 404 319 "-" "crusader-worker/1.0"
34.12.132.25 - - [01/Sep/2026:07:03:11 +0200] "GET /.env.backup HTTP/1.1" 404 319 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ซ๐ท
Stara
2026-09-01 04:41:05
(1 hour ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:19:33
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.12.132.25 (25.132.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.132.25 (25.132.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:19:27.370834 2026] [security2:error] [pid 21312:tid 21312] [client 34.12.132.25:46978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mx20.itimetable21.com"] [uri "/wp-config.php~"] [unique_id "apZST9fhmahTF7LSqXt_MwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-01 04:08:01
(1 hour ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Halux
2026-09-01 03:53:55
(2 hours ago)
34.12.132.25 Probing protected path or service
Web App Attack
๐ณ๐ฑ
ParaBug
2026-09-01 03:51:49
(2 hours ago)
34.12.132.25 - - [01/Sep/2026:05:51:49 +0200] "GET /actuator/configprops HTTP/1.1" 301 4726 "-" "cru ...
show more
34.12.132.25 - - [01/Sep/2026:05:51:49 +0200] "GET /actuator/configprops HTTP/1.1" 301 4726 "-" "crusader-worker/1.0"
...
show less
Phishing
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-01 03:50:05
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-01 03:40:04
(2 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
Anonymous
2026-09-01 03:36:04
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.loc ...
show more
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.local HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.example HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /.env HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.old HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.bak HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 02:55:55
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:47:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.132.25 (25.132.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.132.25 (25.132.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:47:03.463517 2026] [security2:error] [pid 2475:tid 2475] [client 34.12.132.25:56594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirklandplumbing.ca"] [uri "/.env"] [unique_id "apY8p7R1izcgLvXYLB0knwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 02:46:32
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
raph
2026-09-01 02:46:22
(3 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
yvoictra
2026-09-01 01:26:38
(4 hours ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 01:22:55
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.12.132.25 (25.132.12.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.12.132.25 (25.132.12.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:22:48.215714 2026] [security2:error] [pid 19442:tid 19442] [client 34.12.132.25:34388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dpcfab.com"] [uri "/.env.old"] [unique_id "apYo6AUZE-5j2he2HaxfZwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack