๐บ๐ธ
crooze.net
2026-09-01 14:05:21
(6 hours ago)
35.231.46.128 - - [01/Sep/2026:10:05:20 -0400] "GET /wp-config.php.swp HTTP/1.1" 401 172 "-" "crusad ...
show more
35.231.46.128 - - [01/Sep/2026:10:05:20 -0400] "GET /wp-config.php.swp HTTP/1.1" 401 172 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฎ๐ฉ
penjaga BRIN
2026-09-01 13:47:50
(6 hours ago)
Suspicious malicious activity
Hacking
๐ท๐ด
clauss
2026-09-01 13:46:28
(6 hours ago)
35.231.46.128 - - [01/Sep/2026:16:46:27 +0300] "GET /.env.old HTTP/1.1" 404 5749 "-" "crusader-worke ...
show more
35.231.46.128 - - [01/Sep/2026:16:46:27 +0300] "GET /.env.old HTTP/1.1" 404 5749 "-" "crusader-worker/1.0"
35.231.46.128 - - [01/Sep/2026:16:46:27 +0300] "GET /.env.dev HTTP/1.1" 404 5749 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ซ๐ฎ
000rosiu
2026-09-01 10:25:54
(9 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env. | UA: crusader-worker/1.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Hazzard
2026-09-01 10:13:23
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
gadix
2026-09-01 09:35:58
(10 hours ago)
[01/Sep/2026:11:35:57.929966 +0200] apacfY7gw4UCWgJHZpfUFAAAABg 35.231.46.128 35578 127.0.0.1 7081
[ ...
show more
[01/Sep/2026:11:35:57.929966 +0200] apacfY7gw4UCWgJHZpfUFAAAABg 35.231.46.128 35578 127.0.0.1 7081
[01/Sep/2026:11:35:57.936857 +0200] apacfY7gw4UCWgJHZpfUFgAAABU 35.231.46.128 35596 127.0.0.1 7081
[01/Sep/2026:11:35:57.941739 +0200] apacfY7gw4UCWgJHZpfUGQAAABY 35.231.46.128 35624 127.0.0.1 7081
...
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-01 09:34:05
(10 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, scanner_ua, source_backup, config_backup, actuator, ignition_debug. Observed by 1 sensor(s); 42 hits.
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 09:24:10
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 09:24:04
(10 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /.env.example HTTP/1.1, GET /ac ...
show more
Bot / scanning and/or hacking attempts: GET /.env.prod HTTP/1.1, GET /.env.example HTTP/1.1, GET /actuator/env HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 08:50:04
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 08:49:57
(11 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-201)
show less
Hacking
๐ช๐ธ
alferez
2026-09-01 08:02:57
(12 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 08:00:07
(12 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
kkw
2026-09-01 06:21:30
(14 hours ago)
[REDACTED] 35.231.46.128 - - [01/Sep/2026:08:21:30 +0200] "GET /.env.old HTTP/1.1" 302 4819 "-" "cru ...
show more
[REDACTED] 35.231.46.128 - - [01/Sep/2026:08:21:30 +0200] "GET /.env.old HTTP/1.1" 302 4819 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 06:10:03
(14 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack