🇺🇸
jormaster3k
2026-09-06 17:34:29
(1 hour ago)
Attack against Apache (too many 404s)
Web App Attack
Anonymous
2026-09-06 16:06:57
(2 hours ago)
34.181.226.165 - - [06/Sep/2026:18:06:57 +0200] "GET /backup.tar.gz HTTP/1.1" 404 567 "-" "Mozilla/5 ...
show more
34.181.226.165 - - [06/Sep/2026:18:06:57 +0200] "GET /backup.tar.gz HTTP/1.1" 404 567 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.181.226.165 - - [06/Sep/2026:18:06:57 +0200] "GET /dump.sql HTTP/1.1" 403 567 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.181.226.165 - - [06/Sep/2026:18:06:57 +0200] "GET /www.zip HTTP/1.1" 404 567 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.181.226.165 - - [06/Sep/2026:18:06:57 +0200] "GET /db.sql HTTP/1.1" 403 567 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.181.226.165 - - [06/Sep/2026:18:06:57 +0200] "GET /dump.tar.gz HTTP/1.1" 404 567 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.181.226.165 - - [06/Sep/2026:18:06:57 +0200] "GET /database.sql HTT
...
show less
Bad Web Bot
Web App Attack
🇫🇮
SamJUK
2026-09-06 12:40:58
(6 hours ago)
Multiple WAF Violations
...
Bad Web Bot
Web App Attack
🇺🇸
ShadowWhisperer
2026-09-06 06:29:15
(12 hours ago)
DOCKER port scan / probe. GET /.env
Port Scan
🇧🇾
lns.bz
2026-09-06 06:28:29
(12 hours ago)
.env scanning [BY]
Web App Attack
🇬🇧
consul.to
2026-09-06 05:22:03
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇭🇺
DumaNet
2026-09-06 04:51:00
(14 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 34.181 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 34.181.226.165
Portion of the log(s):
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusa
show less
Web App Attack
🇩🇪
LRob
2026-09-06 03:21:16
(15 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+2 more) | 2026-09-06 03:21 UTC
show less
Hacking
Web App Attack
🇧🇬
pa4080
2026-09-06 03:06:47
(15 hours ago)
Detected by ModSecurity. Request URI: /.env.prod
Web App Attack
🇬🇧
Celtic
2026-09-06 02:59:08
(16 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 02:58:15
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.226.165 (165.226.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.226.165 (165.226.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:11.144206 2026] [security2:error] [pid 32355:tid 32355] [client 34.181.226.165:43046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kinnen.org"] [uri "/.env.backup"] [unique_id "apzWw6iaLfvcYeQPfphWewAAAHc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-06 02:36:46
(16 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: config_ba ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: config_backup, source_backup, scanner_ua, env_probe, actuator, ignition_debug. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:24:54
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.181.226.165 (165.226.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.181.226.165 (165.226.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:24:50.257699 2026] [security2:error] [pid 23885:tid 23885] [client 34.181.226.165:42112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||murciafm.murciafm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "murciafm.murciafm.com"] [uri "/dump.sql"] [unique_id "apzO8nT9dQpMyp1uOorILQAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
mgarofano80
2026-09-06 02:11:24
(16 hours ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:44:25
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.226.165 (165.226.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.226.165 (165.226.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:44:20.119092 2026] [security2:error] [pid 31503:tid 31503] [client 34.181.226.165:59398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.adonamusic.com"] [uri "/wp-config.php.swp"] [unique_id "apzFdIyus3vFyuNze72GiAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack