๐ฎ๐ณ
evicky2002
2026-08-31 00:01:03
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-29 03:39:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:39:10.409260 2026] [security2:error] [pid 25541:tid 25541] [client 34.182.147.225:52144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3-6trucking.com"] [uri "/.env.production"] [unique_id "apJUXoG7u1DUa0E6zgR8RAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-08-29 03:23:57
(4 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.182.147 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.182.147.225 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.182.147.225 (US/United States/225.147.182.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 02:07:13
(4 days ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-197)
Hacking
๐ฆ๐บ
Proxay Fox
2026-08-29 01:58:12
(4 days ago)
34.182.147.225 - - [29/Aug/2026:11:58:09 +1000] "GET /.env.old HTTP/1.1" 404 1638 "-" "crusader-work ...
show more
34.182.147.225 - - [29/Aug/2026:11:58:09 +1000] "GET /.env.old HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 99 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . dadc60e82bffe9f77b96511ca561fbe1f92d3a8bcdd73c54d2339c052e9a0ea0
34.182.147.225 - - [29/Aug/2026:11:58:09 +1000] "GET /wp-config.php.bak HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 108 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . 412fa5da39303dbca2bc55435d30d3831a37b50c10aa25ed41f63d85d1680e74
34.182.147.225 - - [29/Aug/2026:11:58:09 +1000] "GET /.env.production HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 106 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . 6548947a3cd55c54cbb3c58a2937c51ea67e52cfad9f515cc440ce24c6b3ab49
34.182.147.225 - - [29/Aug/2026:11:58:09 +1000] "GET /wp-config.php.swp HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 108 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . 7053e8873ff732f8c1ce030a63e1bfaef4d401241a6ac7c3e5c71377f9edf950
34.182.147.225 - - [29/Aug/2026:11:58:09 +1000] "GET /.env.prod HTTP/1.1" 404 1638 "-" "crusader
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
โจ
2026-08-29 01:11:13
(4 days ago)
Domain : manorgate.co.uk
Rule : env
2026-08-29 01:08:52 ***hidden-privacy*** GET /.env.example - 443 ...
show more
Domain : manorgate.co.uk
Rule : env
2026-08-29 01:08:52 ***hidden-privacy*** GET /.env.example - 443 - 34.182.147.225 HTTP/1.1 crusader-worker/1.0 - manorgate.co.uk 200 0 0 18963 99 191 - -
show less
Hacking
SQL Injection
๐ฌ๐ง
andypiper
2026-08-29 01:02:42
(4 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-29 00:48:51
(4 days ago)
Try to access /.env
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-29 00:43:17
(4 days ago)
[29/Aug/2026:03:43:16 +0300] -- 34.182.147.225 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.en ...
show more
[29/Aug/2026:03:43:16 +0300] -- 34.182.147.225 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.save HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 00:42:44
(4 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ท๐บ
DZBOT
2026-08-29 00:11:06
(4 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:49:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:49:01.811550 2026] [security2:error] [pid 23946:tid 23946] [client 34.182.147.225:45892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "universitydental.org"] [uri "/.env.old"] [unique_id "apIebdrF1XplxfJll8HpawAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 23:02:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:02:43.746653 2026] [security2:error] [pid 11368:tid 11368] [client 34.182.147.225:32926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.agingworkforcenews.com"] [uri "/wp-config.php.bak"] [unique_id "apITk9bjlzvbnM8Rg8ltiwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-28 22:42:04
(4 days ago)
(nginxENVSCAN) nginx environment-file scanner detected from 34.182.147.225 (US/United States/Distric ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 34.182.147.225 (US/United States/District of Columbia/Washington D.C./225.147.182.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 21:31:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.147.225 (225.147.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:31:43.004075 2026] [security2:error] [pid 24317:tid 24317] [client 34.182.147.225:52772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jockoenterprises.com"] [uri "/wp-config.php~"] [unique_id "apH-P8irIiSAILg57LjAsQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack