Anonymous
2026-09-01 10:22:59
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐จ๐ญ
zynex
2026-09-01 10:13:01
(1 day ago)
URL Probing: /.env
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 08:28:53
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php.bak (+12 more) | 2026-09-01 08:28 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-01 08:22:07
(1 day ago)
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /actuator/env HTTP/1.1" 404 196 "-" "crusader-work ...
show more
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /actuator/env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /.env.backup HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /.env.save HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /storage/logs/laravel.log HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /.env.dev HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /.env.old HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06 +0800] "GET /.env.bak HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.74.229.8 - - [01/Sep/2026:16:22:06
...
show less
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-01 08:17:43
(1 day ago)
[01/Sep/2026:11:17:43 +0300] -- 34.74.229.8 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp ...
show more
[01/Sep/2026:11:17:43 +0300] -- 34.74.229.8 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /wp-config.php.bak HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-01 06:34:50
(1 day ago)
34.74.229.8 - - [01/Sep/2026:08:34:49 +0200] "GET /.env HTTP/1.1" 403 5023 "-" "crusader-worker/1.0" ...
show more
34.74.229.8 - - [01/Sep/2026:08:34:49 +0200] "GET /.env HTTP/1.1" 403 5023 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dwmp
2026-09-01 06:22:34
(1 day ago)
Url probing: /wp-config.php.swp
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:07:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:02.502559 2026] [security2:error] [pid 13857:tid 13857] [client 34.74.229.8:34308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.crazypencil.com"] [uri "/.env.local"] [unique_id "apZrhlUX3PaeSyb3BaQnZQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 05:07:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:07:48.913911 2026] [security2:error] [pid 7013:tid 7013] [client 34.74.229.8:53168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mmailbox.com"] [uri "/.env.example"] [unique_id "apZdpLsAEBdigZ6V3ABPbwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 05:06:03
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:40:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:40:36.026006 2026] [security2:error] [pid 4139:tid 4139] [client 34.74.229.8:37154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hisfavorite.net"] [uri "/wp-config.php.bak"] [unique_id "apZXRDBxYqVPNdXbrss23QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 04:15:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐ฌ๐ง
consul.to
2026-09-01 04:13:07
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:31:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.229.8 (8.229.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:31:27.652425 2026] [security2:error] [pid 12124:tid 12124] [client 34.74.229.8:50798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "octaviomontes.com"] [uri "/.env.example"] [unique_id "apY4_23AHeFIz1G_8nm5EwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 02:24:01
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack