Anonymous
2026-09-06 06:34:02
(9 hours ago)
34.186.82.144 - - [06/Sep/2026:14:33:10 +0800] "GET /.env.local HTTP/1.1" 404 149 "-" "crusader-work ...
show more
34.186.82.144 - - [06/Sep/2026:14:33:10 +0800] "GET /.env.local HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.186.82.144 - - [06/Sep/2026:14:33:10 +0800] "GET /.env.production HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.186.82.144 - - [06/Sep/2026:14:33:10 +0800] "GET /actuator/configprops HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.186.82.144 - - [06/Sep/2026:14:33:10 +0800] "GET /.env.bak HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
34.186.82.144 - - [06/Sep/2026:14:33:10 +0800] "GET /.env.prod HTTP/1.1" 404 149 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
Victor López
2026-09-06 06:26:44
(9 hours ago)
vmi1846086.contaboserver.net 34.186.82.144 - - [06/Sep/2026:01:26:43 -0500] "GET /wp-config.php~ HTT ...
show more
vmi1846086.contaboserver.net 34.186.82.144 - - [06/Sep/2026:01:26:43 -0500] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "crusader-worker/1.0" -
vmi1846086.contaboserver.net 34.186.82.144 - - [06/Sep/2026:01:26:43 -0500] "GET /.env.save HTTP/1.1" 444 0 "-" "crusader-worker/1.0" -
vmi1846086.contaboserver.net 34.186.82.144 - - [06/Sep/2026:01:26:43 -0500] "GET /crusader-404-probe HTTP/1.1" 444 0 "-" "crusader-worker/1.0" -
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:52:08
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (144.82.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (144.82.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:52:02.478735 2026] [security2:error] [pid 1859:tid 1859] [client 34.186.82.144:44702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.eatatlotone.com"] [uri "/wp-config.php.swp"] [unique_id "apzjYvj357_sdZCGE_NxUwAAAHU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:24
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (144.82.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (144.82.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:17.458526 2026] [security2:error] [pid 2213:tid 2213] [client 34.186.82.144:51170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.siciliafamily.com"] [uri "/.env.example"] [unique_id "apzWyRGvQkVthSurQoB4MQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-06 02:48:00
(12 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇩🇪
raph
2026-09-06 02:40:11
(13 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:30:34
(14 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-06 01:00:05
(14 hours ago)
suspicious request in access.log
Web App Attack
🇨🇿
ddw
2026-09-06 00:08:59
(15 hours ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
🇫🇷
✨
2026-09-06 00:05:09
(15 hours ago)
Domain : kirstyschildminding.co.uk
Rule : hack
2026-09-06 00:02:46 ***hidden-privacy*** GET /wp-conf ...
show more
Domain : kirstyschildminding.co.uk
Rule : hack
2026-09-06 00:02:46 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 34.186.82.144 HTTP/1.1 crusader-worker/1.0 - kirstyschildminding.co.uk 404 0 2 12906 114 299 - -
show less
Hacking
SQL Injection
Brute-Force
🇲🇾
Rizzy
2026-09-05 23:59:37
(15 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:21
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (144.82.186.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (144.82.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:15.202858 2026] [security2:error] [pid 8847:tid 8847] [client 34.186.82.144:36640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.totaleventsandtents.com"] [uri "/.env.bak"] [unique_id "apyrp4ATEKov5GEgfc7e0wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
SysAdmin Dylan
2026-09-05 23:30:47
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (US/United States/144.82.186.34.b ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.82.144 (US/United States/144.82.186.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
🇩🇪
FeG Deutschland
2026-09-05 23:03:14
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
ghostwarriors
2026-09-05 22:50:26
(16 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack