๐ญ๐บ
DumaNet
2026-08-30 05:43:00
(3 days ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 30. 02:21:28
Source IP: 34.136 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 30. 02:21:28
Source IP: 34.136.118.27
Portion of the log(s):
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.118.27 - [30/Aug/2026:02:21:28 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ซ๐ท
โจ
2026-08-30 02:06:09
(3 days ago)
Domain : pleskcontrolpanel
Rule : env
2026-08-30 02:04:35 79.171.34.42 GET /.env.prod - 8880 - 34.13 ...
show more
Domain : pleskcontrolpanel
Rule : env
2026-08-30 02:04:35 79.171.34.42 GET /.env.prod - 8880 - 34.136.118.27 crusader-worker/1.0 - 404 0 2 103 - -
show less
Hacking
SQL Injection
๐ณ๐ฑ
wlt-blocker
2026-08-30 02:05:14
(3 days ago)
Unauthorized access to webpage admin
Web App Attack
Anonymous
2026-08-30 01:55:50
(3 days ago)
Sensitive file access attempt
Hacking
๐บ๐ธ
kosada.com
2026-08-30 00:45:07
(3 days ago)
Web vulnerability probing: /.env.example
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-30 00:40:02
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-08-30 00:38:04
(3 days ago)
blocked for webapp attack | path requested: / | seen at 2026-08-30 00:37:30.346 |
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-30 00:29:28
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 22:01:25
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ญ๐บ
miszterx.hu
2026-08-29 06:07:36
(4 days ago)
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 3x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:27:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.136.118.27 (27.118.136.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.118.27 (27.118.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:26:55.429220 2026] [security2:error] [pid 24453:tid 24453] [client 34.136.118.27:55736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.l3l4.com"] [uri "/.env.local"] [unique_id "apJRf_mvsIzJF1c-pkgLqAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:43:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.136.118.27 (27.118.136.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.118.27 (27.118.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:42:54.892460 2026] [security2:error] [pid 28239:tid 28239] [client 34.136.118.27:52044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qu1ck.com"] [uri "/.env.production"] [unique_id "apJHLgQJMNV1v_Xfi1HQ_QAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
entangled_mongoose
2026-08-29 02:26:52
(4 days ago)
Probed /wp-config.php.bak.
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-29 01:19:43
(4 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:48:02
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.136.118.27 (27.118.136.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.118.27 (27.118.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:47:57.369172 2026] [security2:error] [pid 3356582:tid 3356718] [client 34.136.118.27:53710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "propertyinspectorsinc.com"] [uri "/.env.local"] [unique_id "apIsPX_CS5Z3k2TFNp5QwgAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack