🇷🇴
clauss
2026-09-06 06:13:57
(1 day ago)
34.156.151.245 - - [06/Sep/2026:09:13:57 +0300] "GET /.env.backup HTTP/1.1" 403 10384 "-" "crusader- ...
show more
34.156.151.245 - - [06/Sep/2026:09:13:57 +0300] "GET /.env.backup HTTP/1.1" 403 10384 "-" "crusader-worker/1.0"
34.156.151.245 - - [06/Sep/2026:09:13:57 +0300] "GET /.env.example HTTP/1.1" 403 10385 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇫🇮
JLKnoch Software GmbH
2026-09-06 06:08:10
(1 day ago)
CrowdSec crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇭🇺
DumaNet
2026-09-06 05:01:00
(1 day ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:21:17
Source IP: 34.156 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:21:17
Source IP: 34.156.151.245
Portion of the log(s):
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:28:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:28:20.759722 2026] [security2:error] [pid 22014:tid 22014] [client 34.156.151.245:53206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southernstatespool.com"] [uri "/.env.prod"] [unique_id "apzPxCM8hkGRHSkJ8lhl8AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:46:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:45:59.054536 2026] [security2:error] [pid 32631:tid 32631] [client 34.156.151.245:49650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glitchrpg.abraxasstudio.com"] [uri "/.env.dev"] [unique_id "apzF14Hdbl1OZn_KjsgaEgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 01:43:57
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
debestelapp
2026-09-06 01:25:11
(1 day ago)
Web App Attack
🇺🇸
IndigoRidge
2026-09-06 00:28:42
(1 day ago)
[05/Sep/2026:20:28:41.197838 --0400] apyzuWOnqmDwaCdcQ@XnUwAAAY0 34.156.151.245 60860 205.233.18.17 ...
show more
[05/Sep/2026:20:28:41.197838 --0400] apyzuWOnqmDwaCdcQ@XnUwAAAY0 34.156.151.245 60860 205.233.18.17 7081
[05/Sep/2026:20:28:41.197996 --0400] apyzuWjXsgLkEg79yVVZ2wAAABY 34.156.151.245 60836 205.233.18.17 7081
[05/Sep/2026:20:28:41.198191 --0400] apyzuQ25qZDSiHcFNQRdBQAAAFE 34.156.151.245 60846 205.233.18.17 7081
[05/Sep/2026:20:28:41.198340 --0400] apyzuRUNBdWZ3h0TIUYdyAAAAwI 34.156.151.245 60856 205.233.18.17 7081
[05/Sep/2026:20:28:41.198635 --0400] apyzuZVeellSCUfiRdV1ZwAAA1I 34.156.151.245 60866 205.233.18.17 7081
...
show less
Hacking
🇳🇱
MyGlobalFlowers
2026-09-06 00:04:12
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-06 00:02:56
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-06 00:00:39
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:56:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:56:20.555685 2026] [security2:error] [pid 27633:tid 27633] [client 34.156.151.245:50774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aviil.com"] [uri "/wp-config.php.swp"] [unique_id "apysJBo71O-6APq1kzEIpAAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-05 23:55:22
(1 day ago)
Try to access /.env
Web App Attack
Anonymous
2026-09-05 23:34:03
(1 day ago)
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.local | /. ...
show more
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.local | /.env | /.env.save
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:31:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.151.245 (245.151.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:31:24.045380 2026] [security2:error] [pid 3505653:tid 3505680] [client 34.156.151.245:55286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oldcarz.com"] [uri "/.htaccess"] [unique_id "apymTJt-xs6dfcnCXm5wGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack