🇵🇱
Budyn
2026-08-28 19:20:42
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ts3mb.budyn.wtf | URI: /actuator/env | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
Selckie
2026-08-28 19:07:38
(2 hours ago)
fail2ban: NGINX unusual impact
Web App Attack
Anonymous
2026-08-28 16:45:55
(4 hours ago)
34.88.92.149 - - [28/Aug/2026:16:45:53 +0000] "GET /.env.example HTTP/1.1" 404 15262 "-" "crusader-w ...
show more
34.88.92.149 - - [28/Aug/2026:16:45:53 +0000] "GET /.env.example HTTP/1.1" 404 15262 "-" "crusader-worker/1.0" "-"
34.88.92.149 - - [28/Aug/2026:16:45:54 +0000] "GET /.env.prod HTTP/1.1" 404 15256 "-" "crusader-worker/1.0" "-"
34.88.92.149 - - [28/Aug/2026:16:45:54 +0000] "GET /.env.bak HTTP/1.1" 404 15254 "-" "crusader-worker/1.0" "-"
34.88.92.149 - - [28/Aug/2026:16:45:54 +0000] "GET /.env.save HTTP/1.1" 404 15256 "-" "crusader-worker/1.0" "-"
34.88.92.149 - - [28/Aug/2026:16:45:54 +0000] "GET /.env.production HTTP/1.1" 404 15268 "-" "crusader-worker/1.0" "-"
...
show less
Port Scan
Brute-Force
🇺🇸
uchat-ai.com
2026-08-28 15:58:21
(5 hours ago)
IP 34.88.92.149 在过去24小时内进行了 2 次攻击。详细信息: 攻击类型: Restricted File Access Attempt, 攻击信息: No matched data ...
show more
IP 34.88.92.149 在过去24小时内进行了 2 次攻击。详细信息: 攻击类型: Restricted File Access Attempt, 攻击信息: No matched data found; 攻击类型: Restricted File Access Attempt, 攻击信息: No matched data found
show less
Web App Attack
🇳🇱
MM-bot
2026-08-28 15:58:04
(5 hours ago)
URL-probe: HTTP/1.1 GET request on /.env (2026-08-28 17:58:04 UTC+2)
Web App Attack
Hacking
🇺🇸
etu brutus
2026-08-28 12:52:35
(8 hours ago)
34.88.92.149 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
🇩🇪
edena
2026-08-28 12:12:40
(9 hours ago)
34.88.92.149 - - [28/Aug/2026:14:12:39 +0200] "GET /.env HTTP/1.1" 403 303 "-" "crusader-worker/1.0" ...
show more
34.88.92.149 - - [28/Aug/2026:14:12:39 +0200] "GET /.env HTTP/1.1" 403 303 "-" "crusader-worker/1.0"
34.88.92.149 - - [28/Aug/2026:14:12:39 +0200] "GET /.env.local HTTP/1.1" 403 303 "-" "crusader-worker/1.0"
34.88.92.149 - - [28/Aug/2026:14:12:39 +0200] "GET /.env.prod HTTP/1.1" 403 303 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
creechy
2026-08-28 11:14:26
(10 hours ago)
34.88.92.149 - - [28/Aug/2026:04:14:25 -0700] "GET /wp-config.php~ HTTP/1.1" 404 766
...
Hacking
Bad Web Bot
Anonymous
2026-08-28 11:09:12
(10 hours ago)
wordpress_scan attack on /wp-config.php~ | User-Agent: crusader-worker/1.0 | Detected by PortSense A ...
show more
wordpress_scan attack on /wp-config.php~ | User-Agent: crusader-worker/1.0 | Detected by PortSense API security system
show less
Web App Attack
🇲🇾
Rizzy
2026-08-28 10:53:24
(10 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇴
tmiland
2026-08-28 10:31:53
(10 hours ago)
(nginx_444) Nginx 444 34.88.92.149 (FI/Finland/149.92.88.34.bc.googleusercontent.com): 5 in the last ...
show more
(nginx_444) Nginx 444 34.88.92.149 (FI/Finland/149.92.88.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.88.92.149; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.88.92.149 - - [28/Aug/2026:12:31:47 +0200] "GET /.env.bak HTTP/1.1" 444 0 "-" "crusader-worker/1.0" 34.88.92.149 - - [28/Aug/2026:12:31:47 +0200] "GET /crusader-404-probe HTTP/1.1" 444 0 "-" "crusader-worker/1.0" 34.88.92.149 - - [28/Aug/2026:12:31:47 +0200] "GET /env HTTP/1.1" 444 0 "-" "crusader-worker/1.0" 34.88.92.149 - - [28/Aug/2026:12:31:47 +0200] "GET /.env.old HTTP/1.1" 444 0 "-" "crusader-worker/1.0" 34.88.92.149 - - [28/Aug/2026:12:31:47 +0200] "GET /.env.production HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
show less
Brute-Force
🇭🇺
DumaNet
2026-08-28 04:50:00
(16 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 22:22:55
Source IP: 34.88. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 22:22:55
Source IP: 34.88.92.149
Portion of the log(s):
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.88.92.149 - [27/Aug/2026:22:22:55 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-work
show less
Web App Attack
🇺🇸
mw
2026-08-28 00:02:03
(21 hours ago)
GET /.env HTTP/1.1
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-27 22:01:17
(23 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
🇩🇪
Teufel100
2026-08-27 19:45:59
(1 day ago)
ModSecurity rejected a query
Brute-Force
Hacking
Web App Attack