Anonymous
2026-08-27 21:18:02
(12 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.dev HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-08-27 19:50:00
(13 hours ago)
Spring.Boot.Actuator.Unauthorized.Access
Hacking
๐ฎ๐น
CoreTech srl
2026-08-27 19:04:07
(14 hours ago)
cloudlinux2 fail2ban: 2026-08-27 20:58:56,249 fail2ban.actions [1775]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-27 20:58:56,249 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 154.192.250.135cloudlinux2 fail2ban: 2026-08-27 20:58:48,387 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 92.253.31.83 - 2026-08-27 20:58:48cloudlinux2 fail2ban: 2026-08-27 20:59:41,269 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 92.253.31.83 - 2026-08-27 20:59:41cloudlinux2 fail2ban: 2026-08-27 21:00:23,599 fail2ban.filter [1775]: INFO [recidive] Found 92.253.31.83 - 2026-08-27 21:00:23cloudlinux2 fail2ban: 2026-08-27 21:00:23,591 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 92.253.31.83cloudlinux2 fail2ban: 2026-08-27 21:00:22,375 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 34.148.136.243cloudlinux2 fail2ban: 2026-08-27 21:00:23,107 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 92.253.31.83 - 2026-08-27 21:00:23cloudlinux2 fail2ban: 2026-08-27 21:01:05,081 fail2ban.filter [177
show less
Brute-Force
๐ธ๐ช
Juha Jurvanen
2026-08-27 18:23:00
(15 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
crooze.net
2026-08-27 18:05:55
(15 hours ago)
34.136.38.158 - - [27/Aug/2026:14:05:55 -0400] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "crusader ...
show more
34.136.38.158 - - [27/Aug/2026:14:05:55 -0400] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
mygcode.de
2026-08-27 17:30:24
(16 hours ago)
Scanning for Exploits
Bad Web Bot
๐ณ๐ฑ
e.fierstra
2026-08-27 16:38:04
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-08-27 15:47:55
(17 hours ago)
34.136.38.158 - - [27/Aug/2026:18:47:54 +0300] "GET /.env.example HTTP/1.1" 403 146 "-" "crusader-wo ...
show more
34.136.38.158 - - [27/Aug/2026:18:47:54 +0300] "GET /.env.example HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.136.38.158 - - [27/Aug/2026:18:47:54 +0300] "GET /.env.dev HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-08-27 14:57:20
(18 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐ซ๐ท
Octopuce
2026-08-27 14:37:18
(19 hours ago)
Aggressive web search of vulnerable pages: /.env.backup /.env.save /.env /.env.dev /.env.production ...
show more
Aggressive web search of vulnerable pages: /.env.backup /.env.save /.env /.env.dev /.env.production /wp-config.php.bak /wp-config.php~ /.env.ex ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:13:08
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.136.38.158 (158.38.136.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.38.158 (158.38.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:13:04.041936 2026] [security2:error] [pid 6432:tid 6432] [client 34.136.38.158:54244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yakaloco.tracybur.net"] [uri "/wp-config.php~"] [unique_id "apBF8DtezFVLYNMgBd5izwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 13:53:52
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-08-27 13:37:28
(20 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.swp (+12 more) | 2026-08-27 13:37 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:29:00
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.136.38.158 (158.38.136.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.136.38.158 (158.38.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:28:56.342206 2026] [security2:error] [pid 17339:tid 17339] [client 34.136.38.158:35342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bee432.com"] [uri "/wp-config.php~"] [unique_id "apA7mF4sW6LzyZBRXP9yBgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-08-27 13:13:10
(20 hours ago)
http-sensitive-files - IP: 34.136.38.158 - time="2026-08-27T15:13:09+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 34.136.38.158 - time="2026-08-27T15:13:09+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.136.38.158 (US/396982) : 4h ban on Ip 34.136.38.158" module=db
show less
Web App Attack