๐ธ๐ช
vaia.cloud
2026-08-29 03:30:02
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-29 03:18:12
(5 hours ago)
[Sat Aug 29 13:18:11.840413 2026] [security2:error] [pid 732904] [client 34.86.252.189:58008] [clien ...
show more
[Sat Aug 29 13:18:11.840413 2026] [security2:error] [pid 732904] [client 34.86.252.189:58008] [client 34.86.252.189] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "rjryanpartners.com.au"] [uri "/.env.save"] [unique_id "apJPc0ZZWExAaumtFcEBqQAAABE"]
...
show less
Web App Attack
Anonymous
2026-08-29 03:08:40
(5 hours ago)
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env.example HTTP/1.1" 404 196 "-" "crusader-wo ...
show more
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env.example HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env.prod HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env.save HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env.old HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /crusader-404-probe HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env.local HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /.env.bak HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:11:08:40 +0800] "GET /actuator/env HTTP/1.1" 404 196 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/20
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 02:43:47
(6 hours ago)
Blocked by siteaihub.com: auto: matched exact:/.env
Hacking
Bad Web Bot
๐ฌ๐ง
Aetherweb Ark
2026-08-29 02:26:29
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.86.252.189 (US/United States/189.252.86.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.86.252.189 (US/United States/189.252.86.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-29 02:25:53
(6 hours ago)
[Fri Aug 28 20:25:52.819237 2026] [authz_core:error] [pid 1083974:tid 139830939854400] [client 34.86 ...
show more
[Fri Aug 28 20:25:52.819237 2026] [authz_core:error] [pid 1083974:tid 139830939854400] [client 34.86.252.189:50362] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.bak
[Fri Aug 28 20:25:52.820156 2026] [authz_core:error] [pid 1083580:tid 139831778731584] [client 34.86.252.189:50370] AH01630: client denied by server configuration: /var/www/horde/wp-config.php~
[Fri Aug 28 20:25:52.843151 2026] [authz_core:error] [pid 1083974:tid 139830973425216] [client 34.86.252.189:50372] AH01630: client denied by server configuration: /var/www/horde/wp-config.php.swp
...
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-08-29 01:48:20
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:22:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.252.189 (189.252.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.252.189 (189.252.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:22:53.184534 2026] [security2:error] [pid 3363342:tid 3363360] [client 34.86.252.189:49270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "malia97.com"] [uri "/.env.bak"] [unique_id "apI0bW-f09rsyFsPsuS9SQAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-29 01:20:39
(7 hours ago)
Web vulnerability probing: /env
Web App Attack
๐ฎ๐น
madaello
2026-08-29 01:01:00
(7 hours ago)
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /wp-config.php~ HTTP/1.1" 404 31374 "-" "crusade ...
show more
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /wp-config.php~ HTTP/1.1" 404 31374 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /.env.dev HTTP/1.1" 404 31374 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /.env.old HTTP/1.1" 404 31372 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /_ignition/health-check HTTP/1.1" 404 31374 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /.env.example HTTP/1.1" 404 29061 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 29062 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /.env.local HTTP/1.1" 404 31373 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /.env.prod HTTP/1.1" 404 31372 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:03:00:58 +0200] "GET /.env HTTP/1.1" 404 31372 "-" "crusader-w
...
show less
Web App Attack
Anonymous
2026-08-29 01:00:10
(7 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-29 00:41:11
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.252.189 (189.252.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.252.189 (189.252.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:41:03.050679 2026] [security2:error] [pid 17011:tid 17011] [client 34.86.252.189:51988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wordspectrum.com"] [uri "/.env.save"] [unique_id "apIqn8P0upSICkw9TwPr1gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-08-29 00:17:15
(8 hours ago)
34.86.252.189 - - [29/Aug/2026:02:17:14 +0200] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worke ...
show more
34.86.252.189 - - [29/Aug/2026:02:17:14 +0200] "GET /.env.prod HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:02:17:14 +0200] "GET /.env.production HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.86.252.189 - - [29/Aug/2026:02:17:14 +0200] "GET /.env.save HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-08-29 00:08:49
(8 hours ago)
Abuse Detected (16)
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 00:00:38
(8 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack