Anonymous
2026-09-06 05:21:52
(7 hours ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
🇩🇪
FD-IX
2026-09-06 04:40:22
(7 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 03:33:23
(8 hours ago)
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/ ...
show more
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 34.63.171.26
34.63.171.26 - - [05/Sep/2026:22:30:34 -0500]
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
AetherFox
2026-09-06 03:03:04
(9 hours ago)
AetherFox VoidGuard detected: [Sun Sep 06 05:03:02.984272 2026] [authz_core:error] [pid 352527:tid 3 ...
show more
AetherFox VoidGuard detected: [Sun Sep 06 05:03:02.984272 2026] [authz_core:error] [pid 352527:tid 352561] [client 34.63.171.26:47418] AH01630: client denied by server configuration: proxy:https://136.243.123.86/env
[Sun Sep 06 05:03:02.984366 2026] [authz_core:error] [pid 352527:tid 352561] [client 34.63.171.26:47418] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Sun Sep 06 05:03:02.985345 2026] [authz_core:error] [pid 352528:tid 352553] [client 34.63.171.26:47478] AH01630: client denied by server configuration: proxy:https://136.243.123.86/.env.old
[Sun Sep 06 05:03:02.985434 2026] [authz_core:error] [pid 352528:tid 352553] [client 34.63.171.26:47478] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Sun Sep 06 05:03:02.986487 2026] [authz_core:error] [pid 352528:tid 352548] [client 34.63.171.26:47522] AH01630: client denied by server configuration: proxy:https://136.243.123.86/actuator/configprops
...
show less
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-06 02:14:59
(10 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /html/.git/config
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇦🇺
AWW-Admin
2026-09-06 01:45:56
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.63.171.26 (US/United States/26.171.6 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.63.171.26 (US/United States/26.171.63.34.bc.googleusercontent.com)
show less
SQL Injection
🇵🇱
srebrakowski.com
2026-09-06 01:37:23
(10 hours ago)
crowdsec/waf-detected-exploits
Brute-Force
🇬🇧
consul.to
2026-09-06 00:25:00
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
LRob
2026-09-05 21:53:57
(14 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.bak (+10 more) | 2026-09-05 21:53 UTC
show less
Hacking
Web App Attack
🇺🇸
decisionconcepts
2026-09-05 08:02:32
(1 day ago)
34.63.171.26 - - [05/Sep/2026:01:02:31 -0700] "GET /src/.git/config HTTP/1.1" 403 199 "-" "crusader- ...
show more
34.63.171.26 - - [05/Sep/2026:01:02:31 -0700] "GET /src/.git/config HTTP/1.1" 403 199 "-" "crusader-worker/1.0"
34.63.171.26 - - [05/Sep/2026:01:02:31 -0700] "GET /.git/config HTTP/1.1" 403 199 "-" "crusader-worker/1.0"
show less
Brute-Force
SSH
🇩🇪
FeG Deutschland
2026-09-05 01:45:14
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
Philister11
2026-09-05 01:17:32
(1 day ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
🇩🇪
FD-IX
2026-09-04 22:57:39
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-04 22:45:10
(1 day ago)
216 requests with url.path *.git/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-04 21:17:45
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking