🇺🇸
nationaleventpros.com
2026-08-30 11:15:07
(3 hours ago)
vulnerability scan
Web App Attack
🇪🇪
maxxsense
2026-08-30 10:47:46
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.130.78.127 (CA/Canada/127.78.130.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.130.78.127 (CA/Canada/127.78.130.34.bc.googleusercontent.com)
show less
SQL Injection
🇵🇱
Budyn
2026-08-30 02:16:37
(12 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cdn.astropot.tech | URI: /.env.dev | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇮
albionfreemarket.com
2026-08-30 02:11:40
(12 hours ago)
34.130.78.127 - - [30/Aug/2026:02:11:38 +0000] "GET /db.sql HTTP/2.0" 403 171 "-" "Mozilla/5.0 (Maci ...
show more
34.130.78.127 - - [30/Aug/2026:02:11:38 +0000] "GET /db.sql HTTP/2.0" 403 171 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 0.000 "-" "CA"
34.130.78.127 - - [30/Aug/2026:02:11:38 +0000] "GET /backup.sql HTTP/2.0" 403 171 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 0.000 "-" "CA"
...
show less
Bad Web Bot
Web App Attack
🇨🇦
danieljamesbertrand
2026-08-29 17:57:36
(20 hours ago)
fail2ban jail=nginx-access-exploit on canadapaywall (automatic report; categories 19,21)
Bad Web Bot
Web App Attack
🇧🇷
dominioz
2026-08-29 16:35:29
(22 hours ago)
2026-08-29 16:34:40 GET /.git/config - - 34.130.78.127 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS ...
show more
2026-08-29 16:34:40 GET /.git/config - - 34.130.78.127 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 226
2026-08-29 16:34:41 GET /.env - - 34.130.78.127 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 226
2026-08-29 16:34:41 GET /.env.local - - 34.130.78.127 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 226
2026-08-29 16:34:41 GET /.env.production - - 34.130.78.127 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 226
...
show less
Web App Attack
🇫🇷
bazter.pro
2026-08-29 16:06:36
(22 hours ago)
Auto-Ban [2026-08-29 19:06:36]: CRITICAL: .env attack; DC: Google LLC [Paths: 272] | Details: Exploi ...
show more
Auto-Ban [2026-08-29 19:06:36]: CRITICAL: .env attack; DC: Google LLC [Paths: 272] | Details: Exploit trap paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging | Sensitive files/paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging | 404 errors (277): /server/.env, /control-panel/.env, /queue/.env, /includes/phpinfo.php, /public/.env, /old/.env, /var/www/html/.env, /firebase-adminsdk.json, /mail/phpinfo.php, /.env.backup2 (and 262 more)
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-29 15:39:52
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.130.78.127 (127.78.130.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.78.127 (127.78.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:39:46.408205 2026] [security2:error] [pid 29544:tid 29544] [client 34.130.78.127:53232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.digitalcarbonbank.com"] [uri "/.git/config"] [unique_id "apL9Qufi7EdZ2rEAVFk_JQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 15:22:54
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇮🇹
VHosting
2026-08-29 14:55:03
(23 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-08-29 14:20:24
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 13:39:14
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.130.78.127 (CA/Canada/127.78.130.34.bc.go ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.130.78.127 (CA/Canada/127.78.130.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.130.78.127 - - [29/Aug/2026:15:39:10 +0200] "GET /.env HTTP/1.1" 406 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.130.78.127 - - [29/Aug/2026:15:39:10 +0200] "GET /.env.local HTTP/1.1" 406 4887 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.130.78.127 - - [29/Aug/2026:15:39:10 +0200] "GET /.env.production HTTP/1.1" 406 4886 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Port Scan