๐บ๐ธ
TPI-Abuse
2026-09-22 16:41:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:41:17.688554 2026] [security2:error] [pid 9069:tid 9069] [client 34.47.82.185:48418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rendermatrix.com"] [uri "/wp-config.php.swp"] [unique_id "arKvrYvzhGADh9o3_dy3wwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-09-22 16:21:01
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from KR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from KR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: //.env | UA: crusader-worker/1.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
infra-monitor
2026-09-22 16:00:06
(2 days ago)
Automated ban via infra-monitor: suspicious-probe, wordpress-probe, crowdsecurity/http-sensitive-fil ...
show more
Automated ban via infra-monitor: suspicious-probe, wordpress-probe, crowdsecurity/http-sensitive-files, +3 more
show less
Port Scan
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 15:39:52
(2 days ago)
[ti-tinov] Web exploit scanning: 5 suspicious requests detected by fail2ban jail <name>. Example: 34 ...
show more
[ti-tinov] Web exploit scanning: 5 suspicious requests detected by fail2ban jail <name>. Example: 34.47.82.185 - - \[22/Sep/2026:17:39:38 +0200\] "GET /.env.local HTTP/1.1" 403 5930 "-" "crusader-worker/1.0"
34.47.82.185 - - \[22/Sep/2026:17:39:38 +0200\] "GET /.env.prod HTTP/1.1" 403 5930 "-" "crusader-worker/1.0"
34.47.82.185 - - \[22/Sep/2026:17:39:38 +0200\] "GET /.env.backup HTTP/1.1" 403 5930 "-" "crusader-worker/1.0"
34.47.82.185 - - \[22/Sep/2026:17:39:38 +0200\] "GET /.env.bak HTTP/1.1" 403 5930 "-" "crusader-worker/1.0"
34.47.82.185 - - \[22/Sep/2026:17:39:38 +0200\] "GET /.env HTTP/1.1" 403 5930 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:15:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:15:49.282035 2026] [security2:error] [pid 24378:tid 24378] [client 34.47.82.185:57538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mmipro.com"] [uri "/.env"] [unique_id "arKbpWAFcCNEuwcDKs1rUAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 15:14:38
(2 days ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-22 15:13:53
(2 days ago)
34.47.82.185 - - [22/Sep/2026:17:13:29 +0200] "GET /.env.dev HTTP/1.1" 403 5329 "-" "crusader-worker ...
show more
34.47.82.185 - - [22/Sep/2026:17:13:29 +0200] "GET /.env.dev HTTP/1.1" 403 5329 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-09-22 15:13:38
(2 days ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
๐ฆ๐บ
electronico
2026-09-22 15:10:10
(2 days ago)
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /.env.example HTTP/1.1" 404 7421 "-" "crusader-wo ...
show more
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /.env.example HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /crusader-404-probe HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /.env.prod HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /.env.dev HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /storage/logs/laravel.log HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /.env.save HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /.env.backup HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /_ignition/health-check HTTP/1.1" 404 7421 "-" "crusader-worker/1.0"
34.47.82.185 - - [23/Sep/2026:02:10:09 +1100] "GET /actuator/env HTTP/1.1" 404 7421 "-" "crusader-worke
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:43:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:43:28.192336 2026] [security2:error] [pid 20853:tid 20853] [client 34.47.82.185:44258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magnoliahillproductions.com"] [uri "/.env.dev"] [unique_id "arKUELx6CnNmNur1GVsjsAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 14:26:32
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 12:44:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.185 (185.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:44:27.006530 2026] [security2:error] [pid 3295:tid 3295] [client 34.47.82.185:58314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eileensinc.com"] [uri "/wp-config.php.bak"] [unique_id "arJ4K3fvD6aPeTW6qNjC0gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 12:16:07
(2 days ago)
[server.techsupportltd.gr] httpd-config-scan: sites=www.demo.protogerosparts.gr; logs=/var/log/httpd ...
show more
[server.techsupportltd.gr] httpd-config-scan: sites=www.demo.protogerosparts.gr; logs=/var/log/httpd/domains/protogerosparts.gr.demo.log; samples=/.env.prod | /.env | /.env.backup
show less
Hacking
Web App Attack
๐ฉ๐ช
ecs.ge
2026-09-22 12:13:47
(2 days ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-22 11:26:49
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack