๐ฆ๐บ
AWW-Admin
2026-09-01 10:21:37
(16 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.52.189.231 (BE/Belgium/231.189.52.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.52.189.231 (BE/Belgium/231.189.52.34.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
Octopuce
2026-09-01 10:09:48
(28 minutes ago)
Aggressive web search of vulnerable pages: /.env /.env.local /.env.old /.env.save /.env.backup /.env ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /.env.old /.env.save /.env.backup /.env.production /.env.example /.env.prod /.env. ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:45:24
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.52.189.231 (231.189.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.189.231 (231.189.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:45:21.129028 2026] [security2:error] [pid 12121:tid 12121] [client 34.52.189.231:36524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sonajstarplanet.com"] [uri "/wp-config.php~"] [unique_id "apaesfnjUEbwQ-dkyCFx2gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-01 09:43:25
(55 minutes ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:38:41
(59 minutes ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
Ha1fdan
2026-09-01 09:17:35
(1 hour ago)
[2026-09-01T09:17:32Z] 34.52.189.231 '<URI>'
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 08:51:41
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ญ๐บ
DumaNet
2026-09-01 08:35:00
(2 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 01. 05:00:54
Source IP: 34.52. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 01. 05:00:54
Source IP: 34.52.189.231
Portion of the log(s):
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.52.189.231 - [01/Sep/2026:05:00:54 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:42:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.189.231 (231.189.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.189.231 (231.189.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:42:36.667291 2026] [security2:error] [pid 18870:tid 18870] [client 34.52.189.231:35480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluff2.instagenii.com"] [uri "/.env.save"] [unique_id "apaB7GEHaYr5-3fgYccXCQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 07:11:43
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-01 06:54:43
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-01 06:15:57
(4 hours ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-01 05:06:59
(5 hours ago)
[TueSep0107:06:53.3053622026][security2:error][pid1857241:tid1857510][client34.52.189.231:0]ModSecur ...
show more
[TueSep0107:06:53.3053622026][security2:error][pid1857241:tid1857510][client34.52.189.231:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.inserzioniticino.ch\"][uri\"/wp-config.php~\"][unique_id\"apZdbbdrLyRWL-cNJGSYXAAAAMQ\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:37:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.52.189.231 (231.189.52.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.52.189.231 (231.189.52.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:37:50.797476 2026] [security2:error] [pid 31172:tid 31172] [client 34.52.189.231:46296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "houstontenemosunproblema.verdadesreales.com"] [uri "/wp-config.php.bak"] [unique_id "apZWnlARf0DFvRMz4wa9DQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-09-01 02:42:56
(7 hours ago)
34.52.189.231 - - [01/Sep/2026:04:42:55 +0200] "GET /.env.save HTTP/1.1" 404 4618 "-" "crusader-work ...
show more
34.52.189.231 - - [01/Sep/2026:04:42:55 +0200] "GET /.env.save HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.52.189.231 - - [01/Sep/2026:04:42:55 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.52.189.231 - - [01/Sep/2026:04:42:55 +0200] "GET /.env.production HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
show less
Brute-Force