๐ฉ๐ช
kkw
2026-09-22 15:52:12
(1 day ago)
[REDACTED] 34.47.102.39 - - [22/Sep/2026:17:52:11 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 4465 ...
show more
[REDACTED] 34.47.102.39 - - [22/Sep/2026:17:52:11 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 4465 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Holger
2026-09-22 14:58:05
(1 day ago)
URL probing: GET /.env.dev
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:02:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:02:04.465613 2026] [security2:error] [pid 24130:tid 24130] [client 34.47.102.39:54528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "istealmonitors.donnysimonton.com"] [uri "/.env.bak"] [unique_id "arKKXHj_Cw9DtO0Gr-q_OwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-22 13:58:51
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
daveoctober
2026-09-22 13:57:33
(1 day ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
Vano Ganzzz
2026-09-22 13:32:22
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from KR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Pro ...
show more
Triggered Cloudflare WAF (firewallManaged) from KR.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.bak
Timestamp: 2026-09-22T13:32:22Z
Ray ID: a3f1acde3ad2ea0f
UA: crusader-worker/1.0
show less
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-09-22 13:28:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-22 15:23:54,221 fail2ban.filter [1598]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-22 15:23:54,221 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 45.146.55.99 - 2026-09-22 15:23:53cloudlinux2 fail2ban: 2026-09-22 15:23:50,060 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 45.146.55.99 - 2026-09-22 15:23:49cloudlinux2 fail2ban: 2026-09-22 15:24:15,340 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Ban 34.104.135.13cloudlinux2 fail2ban: 2026-09-22 15:24:14,010 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.104.135.13 - 2026-09-22 15:24:14cloudlinux2 fail2ban: 2026-09-22 15:24:14,773 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.104.135.13 - 2026-09-22 15:24:14cloudlinux2 fail2ban: 2026-09-22 15:24:15,346 fail2ban.filter [1598]: INFO [recidive] Found 34.104.135.13 - 2026-09-22 15:24:15cloudlinux2 fail2ban: 2026-09-22 15:24:15,279 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.104.135.13 - 2026-09-22 15:24:15cloudlinux2 fail2ban: 2026-09-22 1
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:24:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:24:25.793079 2026] [security2:error] [pid 27727:tid 27727] [client 34.47.102.39:37332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gfsprod.com"] [uri "/.env"] [unique_id "arKBidzMwyCo9DHkyUNatwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-09-22 13:13:37
(1 day ago)
Brute-Force
Web App Attack
๐ง๐ท
noconex
2026-09-22 13:09:08
(1 day ago)
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php ...
show more
Wazuh Alert | Rule ID: 110100 | Desc: Suricata: Exploit (ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability) 34.47.102.39
show less
Port Scan
Brute-Force
SSH
Anonymous
2026-09-22 13:07:05
(1 day ago)
Automated web scanner. Requested suspicious paths: /.env.dev | /.env.local | /.env.old | /.env | /.e ...
show more
Automated web scanner. Requested suspicious paths: /.env.dev | /.env.local | /.env.old | /.env | /.env.save | /actuator/env | /actuator/configprops | /.env.example | /.env.bak | /_ignition/health-check | /.env.backup | /.env.production, /.env.prod | /.env.old | /.env | /.env.save | /actuator/env | /actuator/configprops | /.env.example | /.env.bak | /_ignition/health-check | /.env.backup | /.env.production. UTC: 2026-09-22 12:34:19.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:45:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:45:05.170809 2026] [security2:error] [pid 615:tid 645] [client 34.47.102.39:34044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elevapro.com"] [uri "/.env.old"] [unique_id "arJ4Uc-OAFL6V8CCXBclvwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-09-22 12:37:08
(1 day ago)
2026-09-22 12:36:44 GET /.env.production - - 34.47.102.39 HTTP/1.1 crusader-worker/1.0 - 301 593
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:27:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.102.39 (39.102.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:27:12.100872 2026] [security2:error] [pid 28030:tid 28030] [client 34.47.102.39:56734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directoryofbikes.com"] [uri "/.env.bak"] [unique_id "arJ0IF-x4j5BLKBnlrhLGQAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 12:16:49
(1 day ago)
[ti-27al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-27al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.47.102.39 - - [22/Sep/2026:14:16:33 +0200] "GET /.env.example HTTP/1.1" 302 6173 "-" "crusader-worker/1.0"
34.47.102.39 - - [22/Sep/2026:14:16:33 +0200] "GET /.env.save HTTP/1.1" 302 6170 "-" "crusader-worker/1.0"
34.47.102.39 - - [22/Sep/2026:14:16:33 +0200] "GET /.env.prod HTTP/1.1" 302 6170 "-" "crusader-worker/1.0"
34.47.102.39 - - [22/Sep/2026:14:16:33 +0200] "GET /.env.bak HTTP/1.1" 302 6169 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack