Anonymous
2026-08-29 03:06:31
(5 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.86.146.222 (US/United States/222.146.86.3 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.86.146.222 (US/United States/222.146.86.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.86.146.222 - - [29/Aug/2026:05:06:26 +0200] "GET /.env.local HTTP/1.1" 406 4831 "-" "crusader-worker/1.0"
34.86.146.222 - - [29/Aug/2026:05:06:26 +0200] "GET /.env.production HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
34.86.146.222 - - [29/Aug/2026:05:06:26 +0200] "GET /.env.prod HTTP/1.1" 406 4832 "-" "crusader-worker/1.0"
show less
Port Scan
π³π±
e.fierstra
2026-08-29 02:29:46
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π«π·
ecode hosting
2026-08-29 02:10:12
(6 hours ago)
Domain : anahtarhastanesi.com
Rule : env
2026-08-29 02:07:09 10.100.1.20 GET /.env.local - 443 - 34. ...
show more
Domain : anahtarhastanesi.com
Rule : env
2026-08-29 02:07:09 10.100.1.20 GET /.env.local - 443 - 34.86.146.222 HTTP/1.1 crusader-worker/1.0 - www.anahtarhastanesi.com 503 0 64 0 106 1365 - -
show less
Hacking
SQL Injection
π¬π§
andypiper
2026-08-29 01:01:38
(7 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
π·π΄
clauss
2026-08-29 00:13:43
(7 hours ago)
34.86.146.222 - - [29/Aug/2026:03:13:43 +0300] "GET /actuator/configprops HTTP/1.1" 404 27 "-" "crus ...
show more
34.86.146.222 - - [29/Aug/2026:03:13:43 +0300] "GET /actuator/configprops HTTP/1.1" 404 27 "-" "crusader-worker/1.0"
34.86.146.222 - - [29/Aug/2026:03:13:43 +0300] "GET /_ignition/health-check HTTP/1.1" 404 27 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 23:00:58
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.146.222 (222.146.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.146.222 (222.146.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:00:51.220189 2026] [security2:error] [pid 28322:tid 28322] [client 34.86.146.222:46398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realdoctorstories.com"] [uri "/.env.old"] [unique_id "apITI8dotusycMi0pjsC9QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 22:44:34
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.86.146.222 (US/United States/222.146 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.86.146.222 (US/United States/222.146.86.34.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-28 22:27:36
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.146.222 (222.146.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.146.222 (222.146.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:27:33.606114 2026] [security2:error] [pid 5712:tid 5712] [client 34.86.146.222:58448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.onlineteacher.info.amybeam.com"] [uri "/.env.local"] [unique_id "apILVYeLAHPO0S62ZUKOMAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
i-turnradio.nl
2026-08-28 22:22:01
(9 hours ago)
2026-08-29 00:22:01 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 21:42:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.146.222 (222.146.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.146.222 (222.146.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:42:32.903293 2026] [security2:error] [pid 24580:tid 24598] [client 34.86.146.222:38188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raxelon.com"] [uri "/.env"] [unique_id "apIAyIm99ISEuRCsFl9v3wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
iulianh
2026-08-28 20:36:52
(11 hours ago)
80,443
Brute-Force
SSH
π©πͺ
Melle
2026-08-28 20:31:37
(11 hours ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.86.146.222 triggered 5 event ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 34.86.146.222 triggered 5 events | Detected: 2026-08-28T20:31:36.925055897Z
show less
Web App Attack
Hacking
π³π±
mieg
2026-08-28 19:10:05
(13 hours ago)
Web vulnerability probing
Brute-Force
Web App Attack
π¦πΊ
paulshipley.com.au
2026-08-28 18:59:27
(13 hours ago)
[Sat Aug 29 04:59:26.302223 2026] [security2:error] [pid 682517] [client 34.86.146.222:47730] [clien ...
show more
[Sat Aug 29 04:59:26.302223 2026] [security2:error] [pid 682517] [client 34.86.146.222:47730] [client 34.86.146.222] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/.env.bak"] [unique_id "apHajnGlwLCp5Hm_IMrAggAAABE"]
...
show less
Web App Attack
πΈπͺ
vaia.cloud
2026-08-28 18:45:38
(13 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack