๐ช๐ธ
pipeline.es
2026-09-29 19:10:43
(2 hours ago)
Web scanning / probing for vulnerable paths | URL: /notifications/.env | Evidence: ciudadesave.aavv. ...
show more
Web scanning / probing for vulnerable paths | URL: /notifications/.env | Evidence: ciudadesave.aavv.com 34.140.61.165 - - [29/Sep/2026:21:09:22 +0200] \"GET /notifications/.env HTTP/1.1\" 404 25363 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=BE 28000 | ASN: GOOGLE-CLOUD-PLATFORM | Country: BE
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 08:59:02
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 04:58:56.594979 2026] [security2:error] [pid 6524:tid 6524] [client 34.140.61.165:42392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "citystreetsalon.com"] [uri "/.git/config"] [unique_id "art90OS2Kqb2-9aiGz3YygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 06:41:01
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:40:54.905533 2026] [security2:error] [pid 20470:tid 20606] [client 34.140.61.165:58084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityofmiddleton.org"] [uri "/.git/config"] [unique_id "artddliBZRf5NBk6T_3ZMgAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 06:18:53
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:18:48.118449 2026] [security2:error] [pid 15963:tid 15963] [client 34.140.61.165:39228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityoffoley.gov"] [uri "/.git/config"] [unique_id "artYSJqQqui5eanOwrzvcgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 05:39:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:39:22.917581 2026] [security2:error] [pid 19244:tid 19244] [client 34.140.61.165:59008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "citadeltitle.com"] [uri "/.git/config"] [unique_id "arn9iga4-JTT7BWXUP8T_AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 04:32:37
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
gamabe
2026-09-25 02:17:55
(4 days ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐ซ๐ท
dynamix
2026-09-24 18:34:55
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
COMAITE
2026-09-23 11:49:16
(6 days ago)
Suspicious URL access.
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 08:51:12
(6 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐จ๐ญ
Origon
2026-09-22 12:26:25
(1 week ago)
http-sensitive-files - IP: 34.140.61.165 - time="2026-09-22T14:26:25+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 34.140.61.165 - time="2026-09-22T14:26:25+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.140.61.165 (BE/396982) : 4h ban on Ip 34.140.61.165" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:15:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.61.165 (165.61.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:15:23.837320 2026] [security2:error] [pid 25611:tid 25611] [client 34.140.61.165:53056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coconut-homes.com"] [uri "/.git/config"] [unique_id "arG6i7wemQZU_xgM-xuwLgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 13:55:05
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 05:46:02
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ฐ
HostingGroup
2026-09-21 03:11:52
(1 week ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 11. First blocked: 2026-09-21.
show less
Bad Web Bot
Web App Attack