🇺🇸
VanKoh
2026-09-06 06:04:19
(5 hours ago)
34.65.66.170 - - [06/Sep/2026:00:04:18 -0600] "GET /.env.prod HTTP/1.1" 404 58187 "-" "crusader-work ...
show more
34.65.66.170 - - [06/Sep/2026:00:04:18 -0600] "GET /.env.prod HTTP/1.1" 404 58187 "-" "crusader-worker/1.0"
34.65.66.170 - - [06/Sep/2026:00:04:18 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.65.66.170 - - [06/Sep/2026:00:04:18 -0600] "GET /env HTTP/1.1" 404 58187 "-" "crusader-worker/1.0"
...
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:54:52
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:54:47.322861 2026] [security2:error] [pid 28743:tid 28743] [client 34.65.66.170:50410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.crazypencil.com"] [uri "/.env.bak"] [unique_id "apzkBz7n1bNEq7ZYLie3igAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 03:30:58
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
✨
2026-09-06 03:07:20
(8 hours ago)
Domain : wordwheel.quilkin.co.uk
Rule : hack
2026-09-06 03:04:30 ***hidden-privacy*** GET /wp-config ...
show more
Domain : wordwheel.quilkin.co.uk
Rule : hack
2026-09-06 03:04:30 ***hidden-privacy*** GET /wp-config.php.bak - 443 - 34.65.66.170 HTTP/1.1 crusader-worker/1.0 - wordwheel.quilkin.co.uk 404 0 2 1360 112 332 - -
show less
Hacking
SQL Injection
Brute-Force
🇺🇸
MatCat
2026-09-06 03:05:10
(8 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 02:58:22
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:16.250588 2026] [security2:error] [pid 27193:tid 27193] [client 34.65.66.170:50512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.anywherecamera.com"] [uri "/.env.example"] [unique_id "apzWyCB-8RsxqA4lkPu-MAAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-06 02:37:24
(9 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, ignition_debug, config_backup, actuator. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:33:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:33:21.162765 2026] [security2:error] [pid 32351:tid 32351] [client 34.65.66.170:36508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "faw.us"] [uri "/.env.save"] [unique_id "apzQ8V-z6310KE_sseTyGQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:58:34
(9 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇷🇺
DZBOT
2026-09-06 01:36:24
(10 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇳🇱
e.fierstra
2026-09-06 01:26:53
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 00:32:41
(11 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇦🇺
Klaverstyn
2026-09-06 00:23:08
(11 hours ago)
Repeated 403 Forbidden responses
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:02:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:02:14.975803 2026] [security2:error] [pid 23445:tid 23445] [client 34.65.66.170:42414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentsavagelaw.com"] [uri "/.env.production"] [unique_id "apythudtAjRiaJ76Ixi42gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:23:04
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.66.170 (170.66.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:23:00.041217 2026] [security2:error] [pid 19577:tid 19577] [client 34.65.66.170:48240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "konar-steenberg.com"] [uri "/.env"] [unique_id "apykVM7g62MXOj5NcFRKJQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack