Anonymous
2026-08-01 17:29:16
(10 hours ago)
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.old HTTP/1.1" 404 442 "-" "crusader-worker/1 ...
show more
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.old HTTP/1.1" 404 442 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.old HTTP/1.1" 404 281 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.local HTTP/1.1" 404 442 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.local HTTP/1.1" 404 281 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.production HTTP/1.1" 404 442 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.production HTTP/1.1" 404 281 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.backup HTTP/1.1" 404 442 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.backup HTTP/1.1" 404 281 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +0200] "GET /.env.prod HTTP/1.1" 404 442 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:19:29:16 +
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 17:22:57
(10 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.bak | 5 distinct paths | UA: crusader-work ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.bak | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 17:16:44
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.12.72 (72.12.86.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.12.72 (72.12.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:16:36.517127 2026] [security2:error] [pid 3059350:tid 3059350] [client 34.86.12.72:57286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smog-test.smogsandiego.com"] [uri "/.env.prod"] [unique_id "am4p9CbD3K9j-Opf9T4InwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 17:11:26
(10 hours ago)
34.86.12.72 - - [01/Aug/2026:19:11:25 +0200] "GET /.env.example HTTP/1.1" 404 152883 "-" "crusader-w ...
show more
34.86.12.72 - - [01/Aug/2026:19:11:25 +0200] "GET /.env.example HTTP/1.1" 404 152883 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Webhoster
2026-08-01 17:05:50
(10 hours ago)
{"ClientAddr":"104.22.101.157:10002","ClientHost":"34.86.12.72","ClientPort":"10002","ClientUsername ...
show more
{"ClientAddr":"104.22.101.157:10002","ClientHost":"34.86.12.72","ClientPort":"10002","ClientUsername":"-","DownstreamContentSize":0,"DownstreamStatus":403,"Duration":62659213,"OriginContentSize":0,"OriginDuration":27286468,"OriginStatus":0,"Overhead":35372745,"RequestAddr":"demo1.timvdberg.dev","RequestContentSize":0,"RequestCount":624584,"RequestHost":"demo1.timvdberg.dev","RequestMethod":"GET","RequestPath":"/.env.save","RequestPort":"-","RequestProtocol":"HTTP/2.0","RequestScheme":"https","RetryAttempts":0,"RouterName":"https-2-omari8kj3ono91z1qv5lbj10-coraza-www@docker","ServiceAddr":"172.16.16.9:8080","ServiceName":"coraza-www@docker","ServiceURL":"http://172.16.16.9:8080","StartLocal":"2026-08-01T17:05:50.194771239Z","StartUTC":"2026-08-01T17:05:50.194771239Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"https","level":"info","msg":"","request_Cf-Connecting-Ip":"34.86.12.72","request_X-Forwarded-For":"34.86.12.72","request_X-Real-Ip":"104.22.101.157",
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-08-01 17:00:17
(11 hours ago)
Environment file probe
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-01 16:45:07
(11 hours ago)
34.86.12.72 - - [01/Aug/2026:12:45:06 -0400] "GET /.env HTTP/1.1" 403 6293 "-" "crusader-worker/1.0" ...
show more
34.86.12.72 - - [01/Aug/2026:12:45:06 -0400] "GET /.env HTTP/1.1" 403 6293 "-" "crusader-worker/1.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-01 16:40:13
(11 hours ago)
Web vulnerability probing: /.env.old
Web App Attack
Anonymous
2026-08-01 16:37:13
(11 hours ago)
34.86.12.72 - - [01/Aug/2026:13:37:12 -0300] "GET /.env HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show more
34.86.12.72 - - [01/Aug/2026:13:37:12 -0300] "GET /.env HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.86.12.72 - - [01/Aug/2026:13:37:12 -0300] "GET /.env.dev HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Port Scan
Anonymous
2026-08-01 16:26:55
(11 hours ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:23:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.12.72 (72.12.86.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.12.72 (72.12.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:23:15.262538 2026] [security2:error] [pid 2197023:tid 2197023] [client 34.86.12.72:58878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ventilatori-industriali.vm-srl.com"] [uri "/.env.production"] [unique_id "am4dc1lwwTOTWUbX5L9LgQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-01 16:10:05
(11 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฆ๐น
nomzamo
2026-08-01 16:03:44
(12 hours ago)
Fail2Ban reported: nginx-credential-scan
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-08-01 15:16:16
(12 hours ago)
Multiple unauthorized connection attempts
Web App Attack
Anonymous
2026-08-01 15:05:01
(12 hours ago)
suspicious request in access.log
Web App Attack