๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:01:37
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ง๐ช
Saec
2026-08-28 16:28:01
(4 days ago)
Jarvis auto-ban: CF top attacker on saec.ovh (26 hits, US)
Port Scan
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-08-28 15:26:35
(4 days ago)
34.139.23.158 - - [28/Aug/2026:17:26:35 +0200] "GET /.env.backup HTTP/1.1" 404 146 "-" "crusader-wor ...
show more
34.139.23.158 - - [28/Aug/2026:17:26:35 +0200] "GET /.env.backup HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:17:26:35 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:17:26:35 +0200] "GET /.env.production HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ช๐ธ
alferez
2026-08-28 14:52:53
(4 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-08-28 14:28:07
(4 days ago)
[FriAug2816:28:02.6952472026][security2:error][pid2760988:tid2761102][client34.139.23.158:0]ModSecur ...
show more
[FriAug2816:28:02.6952472026][security2:error][pid2760988:tid2761102][client34.139.23.158:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.agilityrossoblu.ch.136-243-54-122.cpanel.site\"][uri\"/wp-config.php.bak\"][unique_id\"apGa8oeS8D3ZXjfjSPfRrgAAAQM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 14:07:11
(4 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-08-28 12:28:41
(4 days ago)
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /.env.prod HTTP/1.1" 403 164 "-" "crusader-worke ...
show more
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /.env.prod HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /.env.backup HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /wp-config.php~ HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /.env.old HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /.env.local HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /env HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /.env.production HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.139.23.158 - - [28/Aug/2026:14:28:36 +0200] "GET /crusader-404-probe HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
34.139
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 12:13:03
(4 days ago)
Bot / scanning and/or hacking attempts: GET /crusader-404-probe HTTP/1.1, GET /.env.backup HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:54:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.23.158 (158.23.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.23.158 (158.23.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:54:02.507607 2026] [security2:error] [pid 26975:tid 26975] [client 34.139.23.158:41554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theledmancom.rotarymagnetics.com"] [uri "/.env.bak"] [unique_id "apF22rSK1LQWkrwO_4F2sQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 10:36:01
(4 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.example (+12 more) | 2026-08-28 10:36 UTC
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-28 10:31:23
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฎ๐น
www.tana.it
2026-08-28 04:18:18
(5 days ago)
PHP scan
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-08-27 21:33:36
(5 days ago)
Blocked by YFC Security on https://1904.brixzly.com โ type: directory_scan_attempts
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-08-27 18:44:01
(5 days ago)
CMS/framework probe: 34.139.23.158 - - [27/Aug/2026:20:44:00 +0200] "GET /.env.production HTTP/1.1" ...
show more
CMS/framework probe: 34.139.23.158 - - [27/Aug/2026:20:44:00 +0200] "GET /.env.production HTTP/1.1" 444 0 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
๐ฉ๐ฐ
castipo
2026-08-27 17:57:22
(5 days ago)
nginx-env :: 34.139.23.158 - - [28/Aug/2026:00:57:22 +0700] "GET /.env HTTP/1.1" 444 0 "-" "crusader ...
show more
nginx-env :: 34.139.23.158 - - [28/Aug/2026:00:57:22 +0700] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0" host="[ip]" cfip="-" cfray="-"
show less
Web App Attack
Hacking