๐ณ๐ฑ
Alt255
2026-09-11 15:37:20
(4 weeks ago)
34.138.86.108 - - \[02/Sep/2026:22:23:52 +0200\] "GET /actuator/threaddump HTTP/1.1" 404 63637 "-" " ...
show more
34.138.86.108 - - \[02/Sep/2026:22:23:52 +0200\] "GET /actuator/threaddump HTTP/1.1" 404 63637 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/124.0 Safari/537.36"
34.138.86.108 - - \[02/Sep/2026:22:23:52 +0200\] "GET /actuator/trace HTTP/1.1" 404 95859 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/124.0 Safari/537.36"
34.138.86.108 - - \[02/Sep/2026:22:23:52 +0200\] "GET /actuator/env HTTP/1.1" 404 95859 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/124.0 Safari/537.36"
34.138.86.108 - - \[02/Sep/2026:22:23:52 +0200\] "GET /api/actuator/env HTTP/1.1" 404 95859 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/124.0 Safari/537.36"
34.138.86.108 - - \[02/Sep/2026:22:23:52 +0200\] "GET /access.log HTTP/1.1" 404 63637 "-" "Mozilla/5.0 \(X11\; Lin
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-11 12:24:39
(4 weeks ago)
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /wp-config.php.bak HTTP/1.1" 404 7982 "-" "cru ...
show more
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /wp-config.php.bak HTTP/1.1" 404 7982 "-" "crusader-worker/1.0"
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /.env.bak HTTP/1.1" 404 7982 "-" "crusader-worker/1.0"
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /.env.production HTTP/1.1" 404 7982 "-" "crusader-worker/1.0"
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /.env.dev HTTP/1.1" 404 7982 "-" "crusader-worker/1.0"
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /.env HTTP/1.1" 404 7982 "-" "crusader-worker/1.0"
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /.env.local HTTP/1.1" 404 7982 "-" "crusader-worker/1.0"
34.138.86.108 - - \[06/Sep/2026:01:52:00 +0200\] "GET /.env.prod HTTP/1.1" 404 7982 "-" "crusader-worker/1.0"
34.138.86.108 - - \[06/Sep/2026:01:52:
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-10 21:58:00
(4 weeks ago)
34.138.86.108 - - [10/Sep/2026:17:57:59 -0400] "GET /dump.sql HTTP/1.1" 403 6257 "https://www.snahr. ...
show more
34.138.86.108 - - [10/Sep/2026:17:57:59 -0400] "GET /dump.sql HTTP/1.1" 403 6257 "https://www.snahr.com/dump.sql" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 12:23:20
(1 month ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-08 05:25:03
(1 month ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-08 03:08:35
(1 month ago)
Automatically blocked due to distributed attack
Hacking
๐บ๐ธ
jormaster3k
2026-09-06 10:17:58
(1 month ago)
Attack against Apache (too many 404s)
Web App Attack
๐ซ๐ท
EDSL
2026-09-06 06:37:11
(1 month ago)
[gps.edsl.fr] Blocked by SysWarden Firewall (Web Attack Port 80)
Web App Attack
Hacking
Port Scan
๐ฌ๐ง
openstrike.co.uk
2026-09-06 05:13:14
(1 month ago)
13 attacks on env grabbing URLs, PHP URLs:
GET /.env.save HTTP/1.1
GET /wp-config.php.swp HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 03:52:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.138.86.108 (108.86.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.86.108 (108.86.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:38.663294 2026] [security2:error] [pid 17336:tid 17336] [client 34.138.86.108:60804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tek-front.com"] [uri "/.env.backup"] [unique_id "apzjhtC8wPLbLjAnisKjSgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-06 03:24:05
(1 month ago)
blocked for webapp attack | path requested: / | seen at 2026-09-06 03:23:25.100 |
Web App Attack
๐บ๐ธ
mnsf
2026-09-06 03:05:59
(1 month ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-09-06 03:04:07
(1 month ago)
Fail2Ban: Banned from jail nginx-scan-critical on 3dausdu.de
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 02:59:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.138.86.108 (108.86.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.86.108 (108.86.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:59:47.236958 2026] [security2:error] [pid 19714:tid 19714] [client 34.138.86.108:47036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.muslera.com"] [uri "/.env"] [unique_id "apzXI99EguwNTCTUSYxuwQAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-06 02:56:46
(1 month ago)
Attempted access to sensitive endpoint (/.env.dev) detected. Automated scan or unauthorized probing.
Web App Attack