๐ท๐ด
clauss
2026-09-22 16:57:42
(18 hours ago)
34.79.185.199 - - [22/Sep/2026:19:57:40 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" ...
show more
34.79.185.199 - - [22/Sep/2026:19:57:40 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" "crusader-worker/1.0"
34.79.185.199 - - [22/Sep/2026:19:57:41 +0300] "GET /actuator/env HTTP/2.0" 404 33830 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-22 16:56:14
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
conrad10781
2026-09-22 16:39:17
(18 hours ago)
nginx-dot-env
Web App Attack
๐จ๐ฆ
zXero
2026-09-22 15:37:55
(19 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
๐ณ๐ฑ
Alt255
2026-09-22 15:37:30
(19 hours ago)
[livebd] Web exploit scanning: 6 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[livebd] Web exploit scanning: 6 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.79.185.199 - - [22/Sep/2026:17:37:28 +0200] "GET /.env.dev HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.79.185.199 - - [22/Sep/2026:17:37:28 +0200] "GET /.env.example HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.79.185.199 - - [22/Sep/2026:17:37:28 +0200] "GET /.env.old HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.79.185.199 - - [22/Sep/2026:17:37:28 +0200] "GET /.env.local HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.79.185.199 - - [22/Sep/2026:17:37:28 +0200] "GET /.env.production HTTP/1.1" 404 7875 "-" "crusader-worker/1.0"
34.79.185.199 - - [22/Sep/2026:17:37:28 +0200] "GET /.env.sa
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-09-22 15:22:14
(19 hours ago)
34.79.185.199 - - [22/Sep/2026:17:22:14 +0200] "GET /env HTTP/1.1" 404 4618 "-" "crusader-worker/1.0 ...
show more
34.79.185.199 - - [22/Sep/2026:17:22:14 +0200] "GET /env HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.79.185.199 - - [22/Sep/2026:17:22:14 +0200] "GET /.env.backup HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.79.185.199 - - [22/Sep/2026:17:22:14 +0200] "GET /actuator/env HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
๐ณ๐ฑ
e.fierstra
2026-09-22 15:16:50
(19 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:14:24
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.185.199 (199.185.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.185.199 (199.185.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:14:18.028791 2026] [security2:error] [pid 23183:tid 23183] [client 34.79.185.199:49990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mispar.solutions"] [uri "/.env.save"] [unique_id "arKbSkfaw3AbPnaPAMz6EQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:56:44
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.185.199 (199.185.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.185.199 (199.185.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:56:35.873600 2026] [security2:error] [pid 1433:tid 1433] [client 34.79.185.199:37640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.softwarezz.net"] [uri "/wp-config.php.bak"] [unique_id "arKXI2VUhTszWFDjm7FROQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-22 13:44:15
(21 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 12:30:03
(22 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:24:55
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.79.185.199 (199.185.79.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.79.185.199 (199.185.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:24:48.397966 2026] [security2:error] [pid 32556:tid 32556] [client 34.79.185.199:38030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dianadelapava.com"] [uri "/.env.old"] [unique_id "arJzkE1nfMY7OUE7jiaxtwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-22 12:01:51
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-22 11:15:04
(23 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-22 11:13:25
(23 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack