Anonymous
2026-09-01 13:01:49
(3 minutes ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.178.114.48 (48.114.178.34.bc.googleuserco ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.178.114.48 (48.114.178.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.178.114.48 - - [01/Sep/2026:15:01:47 +0200] "GET /.env.bak HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
34.178.114.48 - - [01/Sep/2026:15:01:47 +0200] "GET /.env.backup HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.178.114.48 - - [01/Sep/2026:15:01:47 +0200] "GET /.env.save HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 12:29:57
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:29:50.501740 2026] [security2:error] [pid 16672:tid 16672] [client 34.178.114.48:51974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdn.customdesignsbybjp.com"] [uri "/wp-config.php~"] [unique_id "apbFPk9TwhqFl-YZ98QY1AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:23:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:23:31.277882 2026] [security2:error] [pid 8515:tid 8521] [client 34.178.114.48:38240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wegelin.kylight.com"] [uri "/.env.backup"] [unique_id "apa1s7ZNSTdbC-C0tNTsLQAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:08:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:08:27.202835 2026] [security2:error] [pid 22240:tid 22380] [client 34.178.114.48:51442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gell.us"] [uri "/.env"] [unique_id "apayK5Kd78aQczgxaEJTHAAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 09:57:46
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 09:55:03
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 08:27:23
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:20:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:20:30.065520 2026] [security2:error] [pid 1913:tid 1913] [client 34.178.114.48:51530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manufacturassantiago.com"] [uri "/.env.bak"] [unique_id "apaKzmY7qORviIohhgraFgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:57:47
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:57:41.682152 2026] [security2:error] [pid 10039:tid 10039] [client 34.178.114.48:47904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salazartransfers.com"] [uri "/.env.old"] [unique_id "apaFdXM0vCRqzUvAvLT5wwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hidemail.app
2026-09-01 07:53:17
(5 hours ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
Anonymous
2026-09-01 07:29:00
(5 hours ago)
Web probing (15 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by C ...
show more
Web probing (15 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐ฉ๐ช
mr.joecat
2026-09-01 07:24:36
(5 hours ago)
34.178.114.48 - - [01/Sep/2026:09:24:35 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" ...
show more
34.178.114.48 - - [01/Sep/2026:09:24:35 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.178.114.48 - - [01/Sep/2026:09:24:35 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.178.114.48 - - [01/Sep/2026:09:24:35 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.178.114.48 - - [01/Sep/2026:09:24:35 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.178.114.48 - - [01/Sep/2026:09:24:35 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:20:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.114.48 (48.114.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:20:02.558014 2026] [security2:error] [pid 18386:tid 18386] [client 34.178.114.48:37452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "musekisses.com"] [uri "/.env.prod"] [unique_id "apZ8opN9PvH4L5yBFkVgZwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 07:12:13
(5 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-01 06:34:05
(6 hours ago)
crowdsecurity/http-sensitive-files
Web App Attack