๐ซ๐ท
Little Iguana
2026-09-10 23:19:41
(1 week ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ง๐ช
Saec
2026-09-09 18:36:53
(1 week ago)
Honeypot caught: /.git/config via time.saec.me. UA: crusader-worker/1.0.
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
IoT Targeted
Anonymous
2026-09-06 03:11:39
(2 weeks ago)
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /site/.git/config HTTP/1.1" 403 164 "-" "crusader ...
show more
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /site/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /backend/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /var/www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /html/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /public/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.74.86.189 - - [06/Sep/2026:05:11:39 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "c
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
mravb
2026-09-06 02:07:01
(2 weeks ago)
34.74.86.189 - - [06/Sep/2026:05:07:00 +0300] "GET /api/.git/config HTTP/1.1" 404 21 "-" "crusader-w ...
show more
34.74.86.189 - - [06/Sep/2026:05:07:00 +0300] "GET /api/.git/config HTTP/1.1" 404 21 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
๐ฆ๐บ
2000cn.com.au
2026-09-05 13:03:47
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ฆ
eGuest
2026-09-05 07:18:08
(2 weeks ago)
34.74.86.189 - - [05/Sep/2026:01:18:07 -0600] "GET /.env HTTP/1.1" 400 264 "-" "crusader-worker/1.0" ...
show more
34.74.86.189 - - [05/Sep/2026:01:18:07 -0600] "GET /.env HTTP/1.1" 400 264 "-" "crusader-worker/1.0"
34.74.86.189 - - [05/Sep/2026:01:18:07 -0600] "GET /.env.local HTTP/1.1" 400 264 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
๐บ๐ธ
NXTwoThou
2026-09-05 06:52:12
(2 weeks ago)
/.env.local
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 14:03:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:03:25.534768 2026] [security2:error] [pid 25753:tid 25753] [client 34.74.86.189:35058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orlihnizdozlin.cz"] [uri "/.env.old"] [unique_id "aprPrQa8mgIDJ04Wt-oHqQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:01:18
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-04 13:47:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:46:56.554559 2026] [security2:error] [pid 11498:tid 11498] [client 34.74.86.189:50006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adonamusic.com"] [uri "/wp-config.php~"] [unique_id "aprL0HqjZ12CpR9MWREeuQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-04 13:04:38
(2 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, actuator, config_backup, ignition_debug. Observed by 1 sensor(s); 42 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 12:21:54
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:21:48.751182 2026] [security2:error] [pid 24447:tid 24447] [client 34.74.86.189:40724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imap.itimetable21.com"] [uri "/.env.backup"] [unique_id "apq33AW9eU9ta-u3aNOwPgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-04 12:05:14
(2 weeks ago)
Abuse Detected (5)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 11:53:09
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.86.189 (189.86.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:53:01.319573 2026] [security2:error] [pid 26246:tid 26246] [client 34.74.86.189:52452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlewizard.com.wizind.com"] [uri "/wp-config.php.bak"] [unique_id "apqxHfqUgH4FIt7IxETVuwAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-04 11:47:13
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 34.74.86.189 (US/United States/189.86.74.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.74.86.189 (US/United States/189.86.74.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack