๐ญ๐บ
DumaNet
2026-08-28 04:51:00
(1 hour ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 22:36:26
Source IP: 34.44. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 22:36:26
Source IP: 34.44.129.91
Portion of the log(s):
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.44.129.91 - [27/Aug/2026:22:36:26 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-work
show less
Web App Attack
๐ฎ๐น
ciccio diddo
2026-08-28 03:35:04
(2 hours ago)
CMS/WP Exploit multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐บ๐ธ
doll.gl
2026-08-27 20:58:37
(8 hours ago)
34.44.129.91 - - [27/Aug/2026:20:58:35 +0000] "GET /wp-config.php.swp HTTP/1.1" 200 395 "-" "crusade ...
show more
34.44.129.91 - - [27/Aug/2026:20:58:35 +0000] "GET /wp-config.php.swp HTTP/1.1" 200 395 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
RogueAutomata
2026-08-27 20:39:54
(9 hours ago)
Detected malicious request: GET /.env.local
Detections triggered: Environment/config probe
Access v ...
show more
Detected malicious request: GET /.env.local
Detections triggered: Environment/config probe
Access via IP addr (v4)
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 18:45:03
(11 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-27 18:33:25
(11 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 18:32:20
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:18:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.129.91 (91.129.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.129.91 (91.129.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:18:24.199487 2026] [security2:error] [pid 11076:tid 11076] [client 34.44.129.91:40942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amychop.com"] [uri "/.env.backup"] [unique_id "apB_cF3Q3ki4V0wvZ_0H9gAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:01:51
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.129.91 (91.129.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.129.91 (91.129.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:01:43.865662 2026] [security2:error] [pid 7686:tid 7686] [client 34.44.129.91:42702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eagleeyesdesign.com.spacerecording.com"] [uri "/wp-config.php.swp"] [unique_id "apBtdwEhJIaCm9shr9x_iwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
JLKnoch Software GmbH
2026-08-27 16:51:19
(13 hours ago)
CrowdSec crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:15:48
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.44.129.91 (91.129.44.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.129.91 (91.129.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:15:40.117841 2026] [security2:error] [pid 26283:tid 26283] [client 34.44.129.91:45728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plazahacienda.com"] [uri "/.env"] [unique_id "apBUnLCq3BQ0RfEvPr3zCwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 14:50:27
(15 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-08-27 14:38:25
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
4server
2026-08-27 14:31:37
(15 hours ago)
[ThuAug2716:31:33.1839472026][security2:error][pid1300476:tid1300614][client34.44.129.91:0]ModSecuri ...
show more
[ThuAug2716:31:33.1839472026][security2:error][pid1300476:tid1300614][client34.44.129.91:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"eimeko.ch\"][uri\"/wp-config.php.bak\"][unique_id\"apBKRaTCVvtm7t0O5r_xPAAAARQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 14:05:56
(15 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack