๐บ๐ธ
antlac1
2026-08-27 21:21:28
(47 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
kkeyser
2026-08-27 20:45:58
(1 hour ago)
GET /.env HTTP/1.1
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-08-27 20:17:04
(1 hour ago)
blocked for webapp attack | path requested: / | seen at 2026-08-27 20:16:22.281 |
Web App Attack
Anonymous
2026-08-27 19:21:33
(2 hours ago)
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /.env.production HTTP/1.1" 404 28386 "-" "crusad ...
show more
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /.env.production HTTP/1.1" 404 28386 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /.env.production HTTP/1.1" 404 28132 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /.env HTTP/1.1" 404 28386 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /.env HTTP/1.1" 404 28132 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /.env.save HTTP/1.1" 404 28386 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /.env.save HTTP/1.1" 404 28132 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /actuator/configprops HTTP/1.1" 404 28386 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:32 +0200] "GET /actuator/configprops HTTP/1.1" 404 28132 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:21:21:33 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 28386 "-" "crusader
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-08-27 19:09:39
(2 hours ago)
34.133.53.168 - - [27/Aug/2026:19:09:38 +0000] "GET /.env.production HTTP/1.1" 403 5360 "-" "crusade ...
show more
34.133.53.168 - - [27/Aug/2026:19:09:38 +0000] "GET /.env.production HTTP/1.1" 403 5360 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:19:09:38 +0000] "GET /_ignition/health-check HTTP/1.1" 404 5357 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:19:09:38 +0000] "GET /actuator/configprops HTTP/1.1" 404 5357 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:19:09:38 +0000] "GET /actuator/env HTTP/1.1" 404 5357 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:19:09:38 +0000] "GET /.env.old HTTP/1.1" 403 5360 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Exploited Host
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 17:51:26
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 17:17:20
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.53.168 (168.53.133.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.53.168 (168.53.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:17:15.141151 2026] [security2:error] [pid 17745:tid 17745] [client 34.133.53.168:59506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lundtrading.com"] [uri "/.env.old"] [unique_id "apBxGyccK0G9MCr66Od-YQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:52:38
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.133.53.168 (168.53.133.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.133.53.168 (168.53.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:52:35.341210 2026] [security2:error] [pid 23468:tid 23468] [client 34.133.53.168:46126] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.letahitibookings.hamiltonbookings.com"] [uri "/wp-config.php.bak"] [unique_id "apBrU0Tbrnqwhv44ggQfYgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:28:50
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.53.168 (168.53.133.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.53.168 (168.53.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:28:46.763154 2026] [security2:error] [pid 7846:tid 7846] [client 34.133.53.168:37152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mathewyoung.com"] [uri "/.env.local"] [unique_id "apBlvkJvDAmXnt12A035DQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-08-27 16:27:37
(5 hours ago)
Excessive HTTP request rate
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:13:32
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.133.53.168 (168.53.133.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.133.53.168 (168.53.133.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:13:28.467370 2026] [security2:error] [pid 23920:tid 24011] [client 34.133.53.168:57258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanguardforthearts.org"] [uri "/.env"] [unique_id "apBiKIslJlwnZ9GwzfDVcQAAAdg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 16:05:10
(6 hours ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-27 15:50:08
(6 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-08-27 15:42:41
(6 hours ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastiria.gr ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.monastiria.gr; logs=/var/log/httpd/domains/monastiria.gr.log; samples=/actuator/env | /.env | /.env.production
show less
Hacking
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 15:29:07
(6 hours ago)
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4421 "-" "crusa ...
show more
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4421 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4420 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /.env HTTP/1.1" 404 4422 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4421 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /.env.local HTTP/1.1" 404 4421 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /actuator/env HTTP/1.1" 404 4420 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4422 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4420 "-" "crusader-worker/1.0"
34.133.53.168 - - [27/Aug/2026:17:29:04 +0200] "GET /actuator/configprops HTTP/1.1" 404
show less
Web App Attack
Brute-Force