๐ฎ๐น
Inartis
2026-08-27 10:55:39
(2 hours ago)
34.96.221.9 - - [27/Aug/2026:12:55:38 +0200] "GET /.env.old HTTP/1.1" 403 384 "-" "crusader-worker/1 ...
show more
34.96.221.9 - - [27/Aug/2026:12:55:38 +0200] "GET /.env.old HTTP/1.1" 403 384 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:12:55:38 +0200] "GET /.env.production HTTP/1.1" 403 384 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:12:55:38 +0200] "GET /.env HTTP/1.1" 403 384 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
GabrielJST
2026-08-27 10:15:48
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.96.221.9 (HK/Hong Kong/9.221.96.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.96.221.9 (HK/Hong Kong/9.221.96.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ซ๐ท
masterguru
2026-08-27 10:09:09
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.96.221.9 (HK/Hong Kong/9.221.96.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.96.221.9 (HK/Hong Kong/9.221.96.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ฎ
mnazibo
2026-08-27 10:00:05
(3 hours ago)
Date: 27/Aug/2026 12:47:23 | Reported IP: 34.96.221.9 mod_security | id: 930130 | HK/group.my_domain ...
show more
Date: 27/Aug/2026 12:47:23 | Reported IP: 34.96.221.9 mod_security | id: 930130 | HK/group.my_domain/- | Connections: 18 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /%2eenv; /.env.; /.env/; //.env; /.ENV; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env;.png; /.env.prod; /.env.production; /.env.save; /wp-config.php~; /wp-config.php.bak; /wp-config.php.swp | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 09:30:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.221.9 (9.221.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.221.9 (9.221.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:29:58.460417 2026] [security2:error] [pid 15409:tid 15409] [client 34.96.221.9:36724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.title36.itaxcenter.com"] [uri "/.env.backup"] [unique_id "apADlvrEpTNDbx18_ZddqwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-27 09:27:37
(3 hours ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:04:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.221.9 (9.221.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.221.9 (9.221.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:04:51.138592 2026] [security2:error] [pid 30700:tid 30700] [client 34.96.221.9:37998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staugustineflyfishing.net"] [uri "/.env.local"] [unique_id "ao_9s0wLhA95iSWCTW7wwwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-27 08:50:15
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 08:41:09
(4 hours ago)
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4438 "-" "crusader-w ...
show more
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /wp-config.php~ HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 4437 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /.env HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /.env.example HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /.env.save HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /env HTTP/1.1" 404 4438 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /.env.bak HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
34.96.221.9 - - [27/Aug/2026:10:41:07 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
34.96.221.9 - - [27
show less
Web App Attack
Brute-Force
๐ซ๐ท
ecode hosting
2026-08-27 08:36:05
(4 hours ago)
Domain : ceokariyer.org
Rule : hack
2026-08-27 08:34:24 10.100.1.20 GET /wp-config.php.bak - 443 - 3 ...
show more
Domain : ceokariyer.org
Rule : hack
2026-08-27 08:34:24 10.100.1.20 GET /wp-config.php.bak - 443 - 34.96.221.9 HTTP/1.1 crusader-worker/1.0 - www.ceokariyer.org 404 0 64 0 107 435 - -
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
MatCat
2026-08-27 08:05:07
(4 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐ฉ๐ช
4server
2026-08-27 07:13:05
(5 hours ago)
[ThuAug2709:13:02.7199652026][security2:error][pid838665:tid838714][client34.96.221.9:0]ModSecurity: ...
show more
[ThuAug2709:13:02.7199652026][security2:error][pid838665:tid838714][client34.96.221.9:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.hosting-royal.ch.136-243-54-122.cpanel.site\"][uri\"/.env.production\"][unique_id\"ao_jfkS47MsVqPQlUM99UgAAAY0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
oralunal
2026-08-27 06:52:32
(6 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 06:44:29
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.221.9 (9.221.96.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.221.9 (9.221.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:44:21.309905 2026] [security2:error] [pid 4234:tid 4244] [client 34.96.221.9:44868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inongap.com"] [uri "/.env"] [unique_id "ao_cxSN3XfLGuCaKpgmGGQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 06:30:29
(6 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.96.221.9 (HK/Hong Kong/9.221.96.34.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.96.221.9 (HK/Hong Kong/9.221.96.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.96.221.9 - - [27/Aug/2026:08:30:26 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 11881 "-" "crusader-worker/1.0" "-" host=insegnesolution.it.emmeccisolution.it
show less
Port Scan