๐ง๐ช
FrankNeirynck
2026-09-02 16:23:43
(1 hour ago)
[2026-08-31 23:35:34 +0200] [61609] [WARNING] โ ๏ธ ๐ 34.181.134.186 "GET /wp-config.php.swp HTTP/1.1" ...
show more
[2026-08-31 23:35:34 +0200] [61609] [WARNING] โ ๏ธ ๐ 34.181.134.186 "GET /wp-config.php.swp HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
[2026-08-31 23:35:34 +0200] [61609] [WARNING] โ ๏ธ ๐ 34.181.134.186 "GET /wp-config.php~ HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
[2026-08-31 23:35:34 +0200] [61609] [WARNING] โ ๏ธ ๐ 34.181.134.186 "GET /wp-config.php.bak HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:08:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:08:11.832728 2026] [security2:error] [pid 2922:tid 2922] [client 34.181.134.186:50650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.restlesseye.com"] [uri "/.env"] [unique_id "apayGy1C1p9LRBkD2uRW1QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-09-01 11:05:08
(1 day ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 10:45:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:45:00.014032 2026] [security2:error] [pid 21447:tid 21447] [client 34.181.134.186:56816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ozonetreatment.mroxygen.org"] [uri "/.env.bak"] [unique_id "apasrN2g5QxSml9eo4qYsAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:42:05
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.181.134.186 (US/United States/186. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.181.134.186 (US/United States/186.134.181.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 08:53:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:53:19.521451 2026] [security2:error] [pid 30348:tid 30348] [client 34.181.134.186:49728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seize-the-season.com"] [uri "/.env.production"] [unique_id "apaSfyqpKbER11BHNzlUawAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-01 08:47:49
(1 day ago)
WebAttack or semilar from 34.181.134.186
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-01 08:43:55
(1 day ago)
34.181.134.186 - - [01/Sep/2026:14:13:54 +0530] "GET /.env HTTP/1.1" 403 146 "-" "crusader-worker/1. ...
show more
34.181.134.186 - - [01/Sep/2026:14:13:54 +0530] "GET /.env HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:33:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:33:33.322628 2026] [security2:error] [pid 12868:tid 12868] [client 34.181.134.186:53330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maleein.com"] [uri "/.env.local"] [unique_id "apaN3VWztn-85p9lriBbSQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-01 07:55:11
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.181.134.186 (US/United States/186.13 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.181.134.186 (US/United States/186.134.181.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 07:48:20
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ญ
zynex
2026-09-01 07:44:14
(1 day ago)
URL Probing: /wp-config.php~
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 07:04:03
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:39:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.134.186 (186.134.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:39:21.665322 2026] [security2:error] [pid 226452:tid 226484] [client 34.181.134.186:39422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebiglies.info"] [uri "/.env"] [unique_id "apZzGd8rDBwRmC-l-5gGqQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-09-01 06:32:01
(1 day ago)
...
Web Spam
Brute-Force
Web App Attack