๐ฎ๐ณ
evicky2002
2026-08-31 00:01:03
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
Catalin Negru
2026-08-30 22:21:24
(1 day ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ง๐ช
webbie
2026-08-30 03:53:07
(1 day ago)
34.132.83.76 - - [30/Aug/2026:05:53:06 +0200] "GET /actuator/configprops HTTP/1.1" 404 5220 "-" "cru ...
show more
34.132.83.76 - - [30/Aug/2026:05:53:06 +0200] "GET /actuator/configprops HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.132.83.76 - - [30/Aug/2026:05:53:06 +0200] "GET /.env.old HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.132.83.76 - - [30/Aug/2026:05:53:06 +0200] "GET /.env.example HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.132.83.76 - - [30/Aug/2026:05:53:06 +0200] "GET /.env HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
34.132.83.76 - - [30/Aug/2026:05:53:06 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 5220 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-08-30 01:52:58
(2 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 22:00:15
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ฟ๐ฆ
conure.sh
2026-08-29 12:01:38
(2 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ญ๐บ
DumaNet
2026-08-29 03:53:00
(2 days ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 22:17:18
Source IP: 34.132 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 22:17:18
Source IP: 34.132.83.76
Portion of the log(s):
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.132.83.76 - [28/Aug/2026:22:17:18 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ธ
daveoctober
2026-08-29 03:01:18
(2 days ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-29 02:58:58
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฆ๐บ
2000cn.com.au
2026-08-29 01:19:48
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
andypiper
2026-08-29 01:01:09
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:14:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.132.83.76 (76.83.132.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.132.83.76 (76.83.132.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:14:36.609987 2026] [security2:error] [pid 22290:tid 22290] [client 34.132.83.76:47940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cp.graner.us"] [uri "/.env.save"] [unique_id "apIkbKQBaiMUAF1Yxi5WkQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:08:48
(3 days ago)
Abuse Detected (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 22:42:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.132.83.76 (76.83.132.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.132.83.76 (76.83.132.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:42:12.467187 2026] [security2:error] [pid 32179:tid 32179] [client 34.132.83.76:42084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anchorroots.com"] [uri "/wp-config.php~"] [unique_id "apIOxCHjqPIClSnIUF0elQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
rellik
2026-08-28 22:01:00
(3 days ago)
Brute Force Scanning Critical Directories
Hacking
Brute-Force
Web App Attack