Anonymous
2026-09-01 07:27:26
(14 hours ago)
34.34.147.121 - - [01/Sep/2026:01:25:34 -0300] "GET /.env.production HTTP/1.1" 403 1810 "-" "crusade ...
show more
34.34.147.121 - - [01/Sep/2026:01:25:34 -0300] "GET /.env.production HTTP/1.1" 403 1810 "-" "crusader-worker/1.0"
34.34.147.121 - - [01/Sep/2026:01:25:34 -0300] "GET /.env.local HTTP/1.1" 403 1810 "-" "crusader-worker/1.0"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-01 05:23:55
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:23:47.563513 2026] [security2:error] [pid 11679:tid 11679] [client 34.34.147.121:46582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evtoy.danged.com"] [uri "/wp-config.php.bak"] [unique_id "apZhY8s81RwD39D0iUoo9wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:33:05
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:32:59.756522 2026] [security2:error] [pid 19880:tid 19880] [client 34.34.147.121:54982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackstarmgmt.com"] [uri "/.env"] [unique_id "apZVe1AUciBAWBL0j6B7VgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:25:35
(17 hours ago)
2026-09-01 01:25:34,967 fail2ban.actions [2634180]: NOTICE [nginx-wordpress-scan] Ban 34.34. ...
show more
2026-09-01 01:25:34,967 fail2ban.actions [2634180]: NOTICE [nginx-wordpress-scan] Ban 34.34.147.121
2026-09-01 01:25:35,002 fail2ban.actions [2634180]: NOTICE [panels-8081] Ban 34.34.147.121
2026-09-01 01:25:35,023 fail2ban.actions [2634180]: NOTICE [nginx-forbidden] Ban 34.34.147.121
...
show less
Brute-Force
SSH
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 04:14:08
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-01 03:42:00
(17 hours ago)
Web probing (15 hits in 24h) on analytics.beeldentuinrolduc.nl: sensitive-path scans and/or 404 burs ...
show more
Web probing (15 hits in 24h) on analytics.beeldentuinrolduc.nl: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:35:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:35:17.140183 2026] [security2:error] [pid 9701:tid 9798] [client 34.34.147.121:39090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinglips.com"] [uri "/.env.production"] [unique_id "apZH9TeTJ-AG_xCOHscCmQAAAgk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-01 02:38:37
(18 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:23:52
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:23:47.922981 2026] [security2:error] [pid 20736:tid 20736] [client 34.34.147.121:34166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greed.wisk.org"] [uri "/.env.old"] [unique_id "apY3M0dchkYFro2uvTqOlAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 02:20:15
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
Marc
2026-09-01 02:12:25
(19 hours ago)
34.34.147.121 - - [01/Sep/2026:04:12:25 +0200] "GET /actuator/env HTTP/1.1" 404 4616 "-" "crusader-w ...
show more
34.34.147.121 - - [01/Sep/2026:04:12:25 +0200] "GET /actuator/env HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.34.147.121 - - [01/Sep/2026:04:12:25 +0200] "GET /.env.dev HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.34.147.121 - - [01/Sep/2026:04:12:25 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 00:27:43
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:27:35.712144 2026] [security2:error] [pid 13513:tid 13513] [client 34.34.147.121:35930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.infinite-a.com"] [uri "/.env.local"] [unique_id "apYb98BXhhBbgNsXLhIX9AAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-01 00:15:58
(21 hours ago)
[TueSep0102:15:52.7728552026][security2:error][pid817928:tid818172][client34.34.147.121:0]ModSecurit ...
show more
[TueSep0102:15:52.7728552026][security2:error][pid817928:tid818172][client34.34.147.121:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.hosting-domain-swiss.ch\"][uri\"/.env.save\"][unique_id\"apYZODG6PGpONBGDKqR2KAAAANY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:30:22
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.147.121 (121.147.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:30:16.719752 2026] [security2:error] [pid 11796:tid 11796] [client 34.34.147.121:52656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ccortes.magodarman.com"] [uri "/.env.production"] [unique_id "apYOiFU2bj2MWr0KEhUNYQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xxkodedxx
2026-08-31 23:27:46
(22 hours ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get, 2ร edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get, 2ร edge-block in 10m window.
Origin: BE / AS396982 Google LLC
Active: 23:27:14โ23:27:15 UTC
Volume: 5 HTTP req, 15 honeypot probe(s)
Bait taken: /.env.save, /.env.production, /.env.backup, /.env.bak, /wp-config.php.swp
Status mix: 404ร3 444ร2
Vhost fishing: cards.zvxlabs.com
UA: "crusader-worker/1.0"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack