๐ณ๐ฑ
oisecnet
2026-08-29 21:02:18
(1 day ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-08-29. 555 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-08-29. 555 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:35:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.218.75 (75.218.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.218.75 (75.218.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:35:43.189773 2026] [security2:error] [pid 12394:tid 12394] [client 34.182.218.75:53192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.neilvboyer.arsenaultartistmanagement.com"] [uri "/.env"] [unique_id "apJFf-AtoHkxYUDhqFHCXQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-29 02:29:27
(2 days ago)
Banned by Fail2Ban
Web App Attack
๐ง๐ช
voormedia
2026-08-29 02:21:20
(2 days ago)
Accessed trap at '/actuator/env'
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-08-29 01:11:06
(2 days ago)
34.182.218.75 - - [28/Aug/2026:22:11:06 -0300] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worke ...
show more
34.182.218.75 - - [28/Aug/2026:22:11:06 -0300] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.182.218.75 - - [28/Aug/2026:22:11:06 -0300] "GET /wp-config.php.swp HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.182.218.75 - - [28/Aug/2026:22:11:06 -0300] "GET /.env.save HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.182.218.75 - - [28/Aug/2026:22:11:06 -0300] "GET /storage/logs/laravel.log HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.182.218.75 - - [28/Aug/2026:22:11:06 -0300] "GET /.env.old HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:09:02
(2 days ago)
Abuse Detected (19)
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-28 23:51:45
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 22:05:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.218.75 (75.218.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.218.75 (75.218.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:05:29.672719 2026] [security2:error] [pid 8800:tid 8800] [client 34.182.218.75:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.triplejrealty.com"] [uri "/.env.bak"] [unique_id "apIGKQuHLh5p7zPDGt_ifwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 21:50:02
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-28 21:40:04
(2 days ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-28 21:24:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.218.75 (75.218.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.218.75 (75.218.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:24:18.027108 2026] [security2:error] [pid 31479:tid 31479] [client 34.182.218.75:50996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title41.com"] [uri "/wp-config.php.swp"] [unique_id "apH8gkl78jLg7JfnbLNydQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Gabriel Camargo
2026-08-28 20:08:07
(2 days ago)
34.182.218.75 - - [28/Aug/2026:15:08:06 -0500] "GET /.env.prod HTTP/1.1" 301 178 "-" "crusader-worke ...
show more
34.182.218.75 - - [28/Aug/2026:15:08:06 -0500] "GET /.env.prod HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.182.218.75 - - [28/Aug/2026:15:08:06 -0500] "GET /.env.backup HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.182.218.75 - - [28/Aug/2026:15:08:06 -0500] "GET /.env.production HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
Anonymous
2026-08-28 20:01:02
(2 days ago)
Bot / scanning and/or hacking attempts: GET /actuator/configprops HTTP/1.1, GET /wp-config.php.bak H ...
show more
Bot / scanning and/or hacking attempts: GET /actuator/configprops HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.local HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
Lino Project
2026-08-28 19:50:01
(2 days ago)
34.182.218.75 - - [28/Aug/2026:21:49:59 +0200] "GET /wp-config.php~ HTTP/1.1" 404 5694 "-" "crusader ...
show more
34.182.218.75 - - [28/Aug/2026:21:49:59 +0200] "GET /wp-config.php~ HTTP/1.1" 404 5694 "-" "crusader-worker/1.0"
34.182.218.75 - - [28/Aug/2026:21:49:59 +0200] "GET /.env.save HTTP/1.1" 404 5694 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-28 19:48:45
(2 days ago)
[FriAug2821:48:39.9281162026][security2:error][pid2772287:tid2772454][client34.182.218.75:0]ModSecur ...
show more
[FriAug2821:48:39.9281162026][security2:error][pid2772287:tid2772454][client34.182.218.75:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webmail.mondo-it.ch\"][uri\"/.env.local\"][unique_id\"apHmF_BbI4rRwXUWqCmHhAAAAU8\"]
show less
Hacking
Web App Attack