🇩🇪
paissangroup
2026-09-05 14:00:50
(2 hours ago)
Multiple WAF Violations
Web App Attack
🇧🇪
sid3windr
2026-09-05 13:59:21
(2 hours ago)
GET /.env (Tarpitted for , wasted 120B)
Web App Attack
🇩🇪
tinect
2026-09-05 10:23:15
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-05 07:16:48
(9 hours ago)
15 attempts against mh-modsecurity-ban on cmdb
Brute-Force
Web App Attack
🇮🇹
Inartis
2026-09-05 07:03:20
(9 hours ago)
34.89.124.154 - - [05/Sep/2026:09:03:19 +0200] "GET /.env.local HTTP/1.1" 404 5644 "-" "crusader-wor ...
show more
34.89.124.154 - - [05/Sep/2026:09:03:19 +0200] "GET /.env.local HTTP/1.1" 404 5644 "-" "crusader-worker/1.0"
34.89.124.154 - - [05/Sep/2026:09:03:19 +0200] "GET /.env HTTP/1.1" 404 5644 "-" "crusader-worker/1.0"
34.89.124.154 - - [05/Sep/2026:09:03:19 +0200] "GET /.env.old HTTP/1.1" 404 5644 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-04 13:35:22
(1 day ago)
URL Probing: /wp-config.php~
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:18:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.89.124.154 (154.124.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.124.154 (154.124.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:18:08.332681 2026] [security2:error] [pid 2463:tid 2463] [client 34.89.124.154:48710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modistat.com"] [uri "/.env.backup"] [unique_id "apq3AJWAGDlxt_17MaOLoAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-04 12:13:08
(1 day ago)
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4482 "-" "crusader ...
show more
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4482 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4480 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /_ignition/health-check HTTP/1.1" 404 4482 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /actuator/env HTTP/1.1" 404 4480 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /.env.local HTTP/1.1" 404 4481 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /.env.save HTTP/1.1" 404 4482 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /.env.dev HTTP/1.1" 404 4482 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4481 "-" "crusader-worker/1.0"
34.89.124.154 - - [04/Sep/2026:14:13:00 +0200] "GET /.env.old HTTP/1.1" 404 4480 "-" "crusader-work
show less
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 11:17:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.89.124.154 (154.124.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.124.154 (154.124.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:17:42.910331 2026] [security2:error] [pid 571760:tid 571760] [client 34.89.124.154:56946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.automatebi.com"] [uri "/wp-config.php.bak"] [unique_id "apqo1k57GzsYQum-IrRWLgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
miszterx.hu
2026-09-04 11:03:50
(1 day ago)
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
🇳🇱
debestelapp
2026-09-04 10:55:11
(1 day ago)
Web App Attack
🇵🇱
TaKeN
2026-09-04 10:28:21
(1 day ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-09-04T12:28:21+02:00 and 2026-09-04T12:28:21+02:00. Sample requested paths: /_ignition/health-check.
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:05:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.89.124.154 (154.124.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.124.154 (154.124.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:05:44.131538 2026] [security2:error] [pid 19479:tid 19479] [client 34.89.124.154:54594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jeffr.com"] [uri "/.env.dev"] [unique_id "apqX-O4c9-Xr1hAXDoLRNQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 09:26:13
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:41:47
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.89.124.154 (154.124.89.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.89.124.154 (154.124.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:41:39.214326 2026] [security2:error] [pid 23465:tid 23465] [client 34.89.124.154:53894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rustcp.rustyog.net|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rustcp.rustyog.net"] [uri "/.env.bak"] [unique_id "apqEQ_bDeNVkFZkEDoSJDgAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack