|
๐ณ๐ด
79.160.15.94
|
|
WordPress (CMS) attack attempts.
Date: 2026 Sep 06. 07:11:23
Source IP: 79.160.15.94
Portion of ...
show more
WordPress (CMS) attack attempts.
Date: 2026 Sep 06. 07:11:23
Source IP: 79.160.15.94
Portion of the log(s):
79.160.15.94 - [06/Sep/2026:07:11:23 +0200] "GET /wp-content/plugins/newsletter/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:11:21 +0200] "GET /wp-content/plugins/sendinblue/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:11:20 +0200] "GET /wp-content/plugins/postmark/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:11:19 +0200] "GET /wp-content/plugins/sparkpost/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:11:19
show less
|
Web App Attack
Hacking
|
|
๐บ๐ธ
35.185.41.59
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 16:41:07
Source IP: 35.185 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 16:41:07
Source IP: 35.185.41.59
Portion of the log(s):
35.185.41.59 - [05/Sep/2026:16:41:07 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
35.185.41.59 - [05/Sep/2026:16:41:07 +0200] "GET /@fs/var/task/.env?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
35.185.41.59 - [05/Sep/2026:16:41:07 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
35.185.41.59 - [05/Sep/2026:16:41:07 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
show less
|
Web App Attack
|
|
๐บ๐ธ
138.197.69.62
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 07:23:14
Source IP: 138.19 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 07:23:14
Source IP: 138.197.69.62
Portion of the log(s):
138.197.69.62 - [06/Sep/2026:07:23:14 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
138.197.69.62 - [06/Sep/2026:07:23:11 +0200] "POST / HTTP/1.1" 500 2751 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
138.197.69.62 - [06/Sep/2026:07:23:08 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
138.197.69.62 - [06/Sep/2026:07:23:05 +0200] "POST / HTTP/1.1" 500 2751 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
|
Web App Attack
|
|
๐ณ๐ด
79.160.15.94
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 07:00:34
Source IP: 79.160 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 07:00:34
Source IP: 79.160.15.94
Portion of the log(s):
79.160.15.94 - [06/Sep/2026:07:00:34 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:00:28 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:00:27 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:00:26 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
79.160.15.94 - [06/Sep/2026:07:00:26 +0200
show less
|
Brute-Force
Web App Attack
|
|
๐บ๐ฟ
94.154.128.11
|
|
WordPress (CMS) attack attempts.
Date: 2026 Sep 05. 16:47:48
Source IP: 94.154.128.11
Portion o ...
show more
WordPress (CMS) attack attempts.
Date: 2026 Sep 05. 16:47:48
Source IP: 94.154.128.11
Portion of the log(s):
94.154.128.11 - [05/Sep/2026:16:47:48 +0200] "GET /wp-content/plugins/gemini/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
94.154.128.11 - [05/Sep/2026:16:47:47 +0200] "GET /wp-content/plugins/anthropic/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
94.154.128.11 - [05/Sep/2026:16:47:47 +0200] "GET /wp-content/plugins/openai/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
94.154.128.11 - [05/Sep/2026:16:47:46 +0200] "GET /wp-content/plugins/alibaba/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
94.154.128.11 - [05/Sep/2026:16:47:45
show less
|
Web App Attack
Hacking
|
|
๐ท๐บ
194.67.120.119
|
|
WordPress (CMS) attack attempts.
Date: 2026 Sep 05. 18:07:55
Source IP: 194.67.120.119
Portion ...
show more
WordPress (CMS) attack attempts.
Date: 2026 Sep 05. 18:07:55
Source IP: 194.67.120.119
Portion of the log(s):
194.67.120.119 - [05/Sep/2026:18:07:55 +0200] "GET /wp-content/plugins/gitlab/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
194.67.120.119 - [05/Sep/2026:18:07:54 +0200] "GET /wp-content/plugins/github/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
194.67.120.119 - [05/Sep/2026:18:07:53 +0200] "GET /wp-content/plugins/telegram/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
194.67.120.119 - [05/Sep/2026:18:07:53 +0200] "GET /wp-content/plugins/slack/ HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
194.67.120.119 - [05/Sep/2026:18:07:52
show less
|
Web App Attack
Hacking
|
|
๐ฒ๐ฆ
196.117.107.155
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 18:09:45
Source IP: 196.11 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 18:09:45
Source IP: 196.117.107.155
Portion of the log(s):
196.117.107.155 - [05/Sep/2026:18:09:45 +0200] "GET /phpinfo.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
196.117.107.155 - [05/Sep/2026:18:09:44 +0200] "GET /phpinfo.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
196.117.107.155 - [05/Sep/2026:18:09:44 +0200] "GET /phpinfo HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
196.117.107.155 - [05/Sep/2026:18:09:44 +0200] "GET /phpinfo HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/108.0.0.0 Safari/537.36"
196.117.107.155 - [05/Sep/2026:18:09:43 +0200] "GET /prod/.env HTTP/1.1" 404
show less
|
Web App Attack
|
|
๐ซ๐ท
169.58.234.137
|
|
WordPress (CMS) attack attempts.
Date: 2026 Sep 05. 19:26:58
Source IP: 169.58.234.137
Portion ...
show more
WordPress (CMS) attack attempts.
Date: 2026 Sep 05. 19:26:58
Source IP: 169.58.234.137
Portion of the log(s):
169.58.234.137 - [05/Sep/2026:19:26:58 +0200] "GET /wp-includes/fonts/ HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.58.234.137 - [05/Sep/2026:19:26:58 +0200] "GET /wp-includes/css/dist/ HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.58.234.137 - [05/Sep/2026:19:26:56 +0200] "GET /wp-includes/css/ HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.58.234.137 - [05/Sep/2026:19:26:53 +0200] "GET /wp-includes/Text/Diff/ HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.58.234.137 - [05/Sep/2026:19:26:52 +0200] "GET /wp-includes/Text/
show less
|
Web App Attack
Hacking
|
|
๐บ๐ธ
141.148.179.64
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 19:45:09
Source IP: 141.14 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 19:45:09
Source IP: 141.148.179.64
Portion of the log(s):
141.148.179.64 - [05/Sep/2026:19:45:09 +0200] "GET /public/fckeditor/editor/filemanager/browser/default/browser.html HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
141.148.179.64 - [05/Sep/2026:19:45:08 +0200] "GET /public/fckeditor/editor/filemanager/browser/default/browser.html HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
141.148.179.64 - [05/Sep/2026:19:45:00 +0200] "GET /manager/fckeditor/editor/filemanager/browser/default/browser.html HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) Ap
show less
|
Web App Attack
|
|
๐บ๐ธ
18.226.253.47
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 20:44:29
Source IP: 18.226 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 20:44:29
Source IP: 18.226.253.47
Portion of the log(s):
18.226.253.47 - [05/Sep/2026:20:44:29 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "wp2shell"
show less
|
Web App Attack
|
|
๐บ๐ธ
144.225.6.184
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 19:58:34
Source IP: 144.22 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 19:58:34
Source IP: 144.225.6.184
Portion of the log(s):
144.225.6.184 - [05/Sep/2026:19:58:34 +0200] "GET /lib/phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 153 "-" "libredtail-http"
144.225.6.184 - [05/Sep/2026:19:58:34 +0200] "GET /lib/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 153 "-" "libredtail-http"
144.225.6.184 - [05/Sep/2026:19:58:34 +0200] "GET /phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 153 "-" "libredtail-http"
144.225.6.184 - [05/Sep/2026:19:58:34 +0200] "GET /phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 153 "-" "libredtail-http"
144.225.6.184 - [05/Sep/2026:19:58:33 +0200] "GET /phpunit/phpunit/Util/PHP/eval-stdin.php HTTP/1.1" 404 153 "-" "libredtail-http"
144.225.6.184 - [05/Sep/2026:19:58:33 +0200] "GET /phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 153 "-" "libredtail-http"
144.225.6.184 - [05/Sep/2026:19:58:33 +0200] "GET /vendor/vendor/phpunit/phpunit/src/Util/PHP
show less
|
Web App Attack
|
|
๐ฎ๐ณ
20.198.7.31
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 21:09:52
Source IP: 20.198 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 21:09:52
Source IP: 20.198.7.31
Portion of the log(s):
20.198.7.31 - [05/Sep/2026:21:09:52 +0200] "GET /user.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.198.7.31 - [05/Sep/2026:21:09:52 +0200] "GET /hehe.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.198.7.31 - [05/Sep/2026:21:09:52 +0200] "GET /goods.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.198.7.31 - [05/Sep/2026:21:09:52 +0200] "GET /randkeyword.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
20.198.7.31 - [05/Sep/2026:21:09:52 +0200] "GET /about.php HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windo
show less
|
Web App Attack
|
|
๐ซ๐ท
176.31.163.34
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 21:43:32
Source IP: 176.31 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 21:43:32
Source IP: 176.31.163.34
Portion of the log(s):
176.31.163.34 - [05/Sep/2026:21:43:32 +0200] "GET /.env.save HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.31.163.34 - [05/Sep/2026:21:43:32 +0200] "GET /.env.old HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.31.163.34 - [05/Sep/2026:21:43:32 +0200] "GET /.env HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.31.163.34 - [05/Sep/2026:21:43:31 +0200] "GET /wp-config.php.txt HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
176.31.163.34 - [05/Sep/2026:21:43:31 +0200] "GET /wp-config.php.orig HTTP/1.1" 404 555
show less
|
Web App Attack
|
|
๐บ๐ธ
129.121.74.222
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 21:51:10
Source IP: 129.12 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 21:51:10
Source IP: 129.121.74.222
Portion of the log(s):
129.121.74.222 - [05/Sep/2026:21:51:10 +0200] "GET /admin/editor/filemanager/browser/default/browser.html HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
129.121.74.222 - [05/Sep/2026:21:51:10 +0200] "GET /admin/editor/filemanager/browser/default/browser.html HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.201 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
129.121.74.222 - [05/Sep/2026:21:51:01 +0200] "GET /editor/filemanager/browser/default/browser.html HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Ch
show less
|
Web App Attack
|
|
๐ง๐ช
34.156.151.245
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:21:17
Source IP: 34.156 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:21:17
Source IP: 34.156.151.245
Portion of the log(s):
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.156.151.245 - [05/Sep/2026:22:21:17 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
|
Web App Attack
|
|
๐ช๐ธ
34.175.186.53
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:22:43
Source IP: 34.175 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:22:43
Source IP: 34.175.186.53
Portion of the log(s):
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.175.186.53 - [05/Sep/2026:22:22:43 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
|
Web App Attack
|
|
๐ญ๐ฐ
34.92.184.192
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:38:44
Source IP: 34.92. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:38:44
Source IP: 34.92.184.192
Portion of the log(s):
34.92.184.192 - [05/Sep/2026:22:38:44 +0200] "GET /db.sql HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.92.184.192 - [05/Sep/2026:22:38:44 +0200] "GET /backup.rar HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.92.184.192 - [05/Sep/2026:22:38:44 +0200] "GET /sql.gz HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.92.184.192 - [05/Sep/2026:22:38:44 +0200] "GET /backup.tar.gz HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.92.184.192 - [05/Sep/2026:22:38:44 +0200] "GET /backup.sql HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gec
show less
|
Web App Attack
|
|
๐บ๐ธ
34.135.31.75
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:41:06
Source IP: 34.135 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:41:06
Source IP: 34.135.31.75
Portion of the log(s):
34.135.31.75 - [05/Sep/2026:22:41:06 +0200] "GET /backup.tgz HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.135.31.75 - [05/Sep/2026:22:41:06 +0200] "GET /dump.sql HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.135.31.75 - [05/Sep/2026:22:41:06 +0200] "GET /archive.zip HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.135.31.75 - [05/Sep/2026:22:41:06 +0200] "GET /www.zip HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.135.31.75 - [05/Sep/2026:22:41:06 +0200] "GET /htdocs.zip HTTP/1.1" 404 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko
show less
|
Web App Attack
|
|
๐จ๐ฆ
35.203.115.74
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:58:32
Source IP: 35.203 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 22:58:32
Source IP: 35.203.115.74
Portion of the log(s):
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /.env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.203.115.74 - [05/Sep/2026:22:58:32 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader
show less
|
Web App Attack
|
|
๐ง๐ช
35.233.45.153
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 35.233 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 35.233.45.153
Portion of the log(s):
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.production HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
35.233.45.153 - [05/Sep/2026:23:18:05 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
|
Web App Attack
|
|
๐บ๐ธ
34.106.88.218
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:17:04
Source IP: 34.106 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:17:04
Source IP: 34.106.88.218
Portion of the log(s):
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /.env.local HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.106.88.218 - [05/Sep/2026:23:17:04 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
|
Web App Attack
|
|
๐บ๐ธ
34.181.226.165
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 34.181 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:18:05
Source IP: 34.181.226.165
Portion of the log(s):
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /wp-config.php~ HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /.env.backup HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.181.226.165 - [05/Sep/2026:23:18:05 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusa
show less
|
Web App Attack
|
|
๐บ๐ธ
34.136.59.197
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:19:36
Source IP: 34.136 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:19:36
Source IP: 34.136.59.197
Portion of the log(s):
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /.env.old HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /.env.prod HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /crusader-404-probe HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.136.59.197 - [05/Sep/2026:23:19:36 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
|
Web App Attack
|
|
๐บ๐ธ
8.229.26.148
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:38:36
Source IP: 8.229. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 05. 23:38:36
Source IP: 8.229.26.148
Portion of the log(s):
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /_ignition/health-check HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /actuator/configprops HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /actuator/env HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /.env.example HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /.env.save HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
8.229.26.148 - [05/Sep/2026:23:38:36 +0200] "GET /.env.dev HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
show less
|
Web App Attack
|
|
๐บ๐ธ
172.86.90.180
|
|
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 06:25:11
Source IP: 172.86 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 06. 06:25:11
Source IP: 172.86.90.180
Portion of the log(s):
172.86.90.180 - [06/Sep/2026:06:25:11 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.86.90.180 - [06/Sep/2026:06:25:10 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
|
Web App Attack
|