๐ช๐ธ
pipeline.es
2026-09-29 20:38:54
(5 days ago)
Web scanning / probing for vulnerable paths | URL: /admin/.env | Evidence: microsites.grupoeuropa.co ...
show more
Web scanning / probing for vulnerable paths | URL: /admin/.env | Evidence: microsites.grupoeuropa.com 34.101.156.254 - - [29/Sep/2026:22:37:02 +0200] \"GET /admin/.env HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=ID | ASN: GOOGLE-CLOUD-PLATFORM | Country: ID
show less
Port Scan
Web App Attack
๐บ๐ธ
masterguru
2026-09-29 14:33:44
(6 days ago)
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\ ...
show more
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})| (932130-147)
show less
Hacking
๐ง๐ช
cmbplf
2026-09-29 08:35:38
(6 days ago)
697 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 08:11:04
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:10:56.633293 2026] [security2:error] [pid 16332:tid 16332] [client 34.101.156.254:56654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thumbrealty.jasbemarketing.com"] [uri "/.git/config"] [unique_id "artykGo0OVjoVfr__NWnAgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-28 06:16:34
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-28 06:13:03
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-26 15:21:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:21:38.522905 2026] [security2:error] [pid 31297:tid 31297] [client 34.101.156.254:58908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aperturecontrols.com"] [uri "/.git/config"] [unique_id "arfjAoLSC48SbydxE6OH3gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 14:27:27
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:27:19.598244 2026] [security2:error] [pid 31703:tid 31703] [client 34.101.156.254:37508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.apcalculusexamprep.com"] [uri "/.git/config"] [unique_id "arfWR1eZQ7ZU1wfhqSdPmwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 21:29:46
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-25 21:28:45
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:39:04
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:38:59.577778 2026] [security2:error] [pid 25045:tid 25045] [client 34.101.156.254:34318] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.tgt.cescfoundation.org"] [uri "/.git/config"] [unique_id "arV8U__ms9bljSHbKzfXdwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 05:57:39
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-22 11:20:03
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
gurnip
2026-09-22 08:40:59
(1 week ago)
Vulnerability probe of page /.git/config, not found on the server.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:36:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.156.254 (254.156.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:36:33.430375 2026] [security2:error] [pid 27570:tid 27570] [client 34.101.156.254:42072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thewillsmith.anthonyjoseph.us"] [uri "/.git/config"] [unique_id "arHbofBGi36GsGF0ue2bywAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack