🇫🇷
masterguru
2026-09-06 02:41:00
(34 minutes ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-201)
Hacking
🇫🇷
dynamix
2026-09-06 02:01:11
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇲🇾
Rizzy
2026-09-06 01:57:15
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-06 01:36:36
(1 hour ago)
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /actuator/env HTTP/1.1" 404 164 "-" "crusader-wo ...
show more
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /actuator/env HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /.env.prod HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /.env.bak HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /.env.old HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /actuator/configprops HTTP/1.1" 404 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /.env.local HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /wp-config.php~ HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:36:28 +0200] "GET /.env.backup HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34
...
show less
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-06 00:55:10
(2 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:44:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:44:12.291299 2026] [security2:error] [pid 29650:tid 29662] [client 34.39.197.192:54204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abadie.com.uy"] [uri "/.env.prod"] [unique_id "apy3XDK_Ze3cnQ1SOdgvNgAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MBombeck
2026-09-06 00:14:29
(3 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-06 00:09:53
(3 hours ago)
[06/Sep/2026:03:09:52 +0300] -- 34.39.197.192 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env ...
show more
[06/Sep/2026:03:09:52 +0300] -- 34.39.197.192 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.env.old HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:57:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:57:27.781094 2026] [security2:error] [pid 10853:tid 10853] [client 34.39.197.192:57298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.starfi.com"] [uri "/.env.example"] [unique_id "apysZyT6zVXRHO0cm8A1FwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-05 23:47:48
(3 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:07:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:07:34.810649 2026] [security2:error] [pid 11839:tid 11839] [client 34.39.197.192:54120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalhay.gulftelecom.com"] [uri "/.env.example"] [unique_id "apygtqCoBVpnWKI9Ly0yvgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-09-05 23:02:45
(4 hours ago)
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.swp
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-05 22:57:04
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:40:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.197.192 (192.197.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:40:26.374840 2026] [security2:error] [pid 3622:tid 3622] [client 34.39.197.192:50474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "genevainvestors.internetnameregistration.com"] [uri "/wp-config.php~"] [unique_id "apyaWuOUqHffOirD2OQpAQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
cybertailor
2026-09-05 22:37:27
(4 hours ago)
34.39.197.192 - - [06/Sep/2026:03:37:24 +0500] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0 ...
show more
34.39.197.192 - - [06/Sep/2026:03:37:24 +0500] "GET /.env HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:37:24 +0500] "GET /.env.prod HTTP/1.1" 404 1279 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:37:24 +0500] "GET /.env.save HTTP/1.1" 404 1279 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:37:24 +0500] "GET /.env.dev HTTP/1.1" 404 1278 "-" "crusader-worker/1.0"
34.39.197.192 - - [06/Sep/2026:03:37:24 +0500] "GET /wp-config.php~ HTTP/1.1" 404 1284 "-" "crusader-worker/1.0"
...
show less
Web App Attack