๐ณ๐ฑ
ParaBug
2026-08-01 14:59:18
(19 minutes ago)
34.185.238.73 - - [01/Aug/2026:16:59:17 +0200] "GET /.env.save HTTP/1.1" 404 4598 "-" "crusader-work ...
show more
34.185.238.73 - - [01/Aug/2026:16:59:17 +0200] "GET /.env.save HTTP/1.1" 404 4598 "-" "crusader-worker/1.0"
...
show less
Phishing
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-01 14:16:24
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 34.185.238.73 (DE/Germany/73.238.185.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.185.238.73 (DE/Germany/73.238.185.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
Nevermind
2026-08-01 14:09:02
(1 hour ago)
34.185.238.73 - - [01/Aug/2026:16:09:01 +0200] "GET /.env.backup HTTP/1.1" 403 6278 "-" "crusader-wo ...
show more
34.185.238.73 - - [01/Aug/2026:16:09:01 +0200] "GET /.env.backup HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
34.185.238.73 - - [01/Aug/2026:16:09:01 +0200] "GET /.env.local HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
34.185.238.73 - - [01/Aug/2026:16:09:01 +0200] "GET /.env.prod HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
34.185.238.73 - - [01/Aug/2026:16:09:01 +0200] "GET /.env.old HTTP/1.1" 403 6278 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-01 13:39:50
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:20:52
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-08-01 13:19:16
(1 hour ago)
CMS/framework probe: 34.185.238.73 - - [01/Aug/2026:15:19:15 +0200] "GET /.env HTTP/1.1" 444 0 "-" " ...
show more
CMS/framework probe: 34.185.238.73 - - [01/Aug/2026:15:19:15 +0200] "GET /.env HTTP/1.1" 444 0 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=DE
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 13:12:16
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 13:10:03
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 12:37:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.238.73 (73.238.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.238.73 (73.238.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:37:32.271944 2026] [security2:error] [pid 751896:tid 751896] [client 34.185.238.73:46906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.estate36.yankeetownfishing.com"] [uri "/.env.old"] [unique_id "am3ojIFzn9yv7Rayz1cpyAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 12:27:51
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ช๐ธ
pipeline.es
2026-08-01 11:57:38
(3 hours ago)
Port scanning / recon | Evidence: date=2026-08-01 time=13:57:08 devname="[redacted]" devid="[redacte ...
show more
Port scanning / recon | Evidence: date=2026-08-01 time=13:57:08 devname="[redacted]" devid="[redacted]" eventtime=1785585428436942290 tz=\"+0200\" logid=\"0000000013\" type=\"traffic\" subtype=\"forward\" level=\"notice\" vd="[redacted]" srcip=34.185.238.73 srcport=35746 srcintf="[redacted]" srcintfrole=\"wan\" dstip=[redacted] dstport=443 dstintf="[redacted]" dstintfrole=\"lan\" srccountry=\"Germany\" dstcountry=\"Spain\" session | ASN: GOOGLE-CLOUD-PLATFORM | Country: DE
show less
Port Scan
Web App Attack
๐ฌ๐ง
consul.to
2026-08-01 11:56:14
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 11:43:39
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 11:28:19
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 09:46:22
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.238.73 (73.238.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.238.73 (73.238.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 05:46:16.786627 2026] [security2:error] [pid 317707:tid 317707] [client 34.185.238.73:52734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aupapierjaponais.com"] [uri "/.env"] [unique_id "am3AaJ8NhIahOKVbYPrctwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack