Anonymous
2026-09-05 07:42:21
(9 hours ago)
34.179.135.39 - - [05/Sep/2026:09:42:21 +0200] "GET /.env.production HTTP/1.1" 200 10348 "-" "crusad ...
show more
34.179.135.39 - - [05/Sep/2026:09:42:21 +0200] "GET /.env.production HTTP/1.1" 200 10348 "-" "crusader-worker/1.0"
...
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
Web App Attack
SSH
🇫🇮
mnazibo
2026-09-05 07:00:29
(10 hours ago)
Date: Sep 05 09:55:54 2026 EAT | Reported IP: 34.179.135.39 mod_security | id: 920440 920500 930130 ...
show more
Date: Sep 05 09:55:54 2026 EAT | Reported IP: 34.179.135.39 mod_security | id: 920440 920500 930130 949110 | DE/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; Attempt to access a backup or working file; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted F
show less
SQL Injection
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 15:19:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:19:45.333959 2026] [security2:error] [pid 2563:tid 2563] [client 34.179.135.39:49482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mainescentsecrets.com"] [uri "/.env"] [unique_id "aprhkSSSbG7k_d0xxAKEtAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:46:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:46:17.997565 2026] [security2:error] [pid 8498:tid 8498] [client 34.179.135.39:52878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chrestian.com.gasoilliquidsdaily.com"] [uri "/wp-config.php.swp"] [unique_id "aprZuaVHFFPHnd5dSghiMAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:46.306784 2026] [security2:error] [pid 9973:tid 9973] [client 34.179.135.39:58652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.manninglandservices.com"] [uri "/wp-config.php.swp"] [unique_id "aprQshtOg0QFTLkXzSwtswAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 13:53:54
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:41:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:41:48.506838 2026] [security2:error] [pid 3074850:tid 3074902] [client 34.179.135.39:57502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unitedonegroup.com"] [uri "/.env.dev"] [unique_id "aprKnADE4i4QbWxJxPwlTAAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-04 13:39:25
(1 day ago)
Login credentials theft attempt
Hacking
🇫🇷
pm33
2026-09-04 13:26:19
(1 day ago)
Wordpress login attempts
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 11:46:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:46:33.001550 2026] [security2:error] [pid 565:tid 565] [client 34.179.135.39:52616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rphenry.com"] [uri "/.env"] [unique_id "apqvmR1CmAoRP90KF1hfTQAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:50:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 10:22:00
(1 day ago)
[04/Sep/2026:13:22:00 +0300] -- 34.179.135.39 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more
[04/Sep/2026:13:22:00 +0300] -- 34.179.135.39 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /storage/logs/laravel.log HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:08:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.135.39 (39.135.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:08:07.876236 2026] [security2:error] [pid 11808:tid 11808] [client 34.179.135.39:38360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathynash.nashes.net"] [uri "/.env.example"] [unique_id "apqYh0IiOWROwlrFSAQX1AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
borbolla
2026-09-04 10:04:39
(1 day ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.env HTTP/1.1" "GET /.env ...
show more
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.env HTTP/1.1" "GET /.env.backup HTTP/1.1" "GET /.env.bak HTTP/1.1"
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-04 09:37:06
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /.env.save HTTP/1.1, GET /wp- ...
show more
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /.env.save HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.bak HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /env HTTP/1.1
show less
Hacking
Web App Attack