🇭🇺
DumaNet
2026-08-29 04:27:00
(10 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 29. 02:17:16
Source IP: 34.24. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 29. 02:17:16
Source IP: 34.24.59.51
Portion of the log(s):
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.24.59.51 - [29/Aug/2026:02:17:16
show less
Web App Attack
🇬🇧
Apache
2026-08-29 03:05:21
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (US/United States/51.59.24.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (US/United States/51.59.24.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-08-29 02:20:14
(12 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇩🇪
maxpower
2026-08-29 01:55:42
(13 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.24.59.51 (US/United States/51.59.24.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.24.59.51 (US/United States/51.59.24.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.24.59.51 - - [29/Aug/2026:03:55:39 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11949 "-" "crusader-worker/1.0" "-" host=tecnousatopescara.it
show less
Port Scan
🇺🇸
mnsf
2026-08-29 00:08:58
(14 hours ago)
Abuse Detected (18)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:40:30
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (51.59.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (51.59.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:40:22.857147 2026] [security2:error] [pid 11983:tid 11983] [client 34.24.59.51:60480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "templegardens.org"] [uri "/.env.save"] [unique_id "apIcZrfSrC88ezjXyPqDtgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:32:39
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (51.59.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (51.59.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:32:33.774443 2026] [security2:error] [pid 1767:tid 1767] [client 34.24.59.51:38094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marketask.bridgital.com"] [uri "/.env.bak"] [unique_id "apIMgT5Ogdn5J1V9DCfREwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
Lunix
2026-08-28 22:23:45
(16 hours ago)
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 18:46:19
(20 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 18:41:14
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (51.59.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.59.51 (51.59.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:41:06.955364 2026] [security2:error] [pid 25571:tid 25571] [client 34.24.59.51:34816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maldonadolawn.com.jbcllcnet.com"] [uri "/.env.example"] [unique_id "apHWQgkpq6M-jchQmGHxBgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-28 18:35:15
(20 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇫🇷
conseilgouz
2026-08-28 18:33:40
(20 hours ago)
hae-7 : Trying access unauthorized files/dir=>/wp-config.php~
Hacking
🇳🇴
jad-abuse
2026-08-28 17:59:08
(21 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, ignition_debug, actuator, source_backup, config_backup. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇩🇪
big-cloud.nl
2026-08-28 17:57:05
(21 hours ago)
Try to access /.env
Web App Attack
Anonymous
2026-08-28 15:36:03
(23 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1
Hacking
Web App Attack