🇪🇸
pipeline.es
2026-09-07 15:35:30
(14 minutes ago)
Web scanning / probing for vulnerable paths | URL: /circleci/.env | Evidence: altovolta.es 34.154.46 ...
show more
Web scanning / probing for vulnerable paths | URL: /circleci/.env | Evidence: altovolta.es 34.154.46.19 - - [07/Sep/2026:17:34:53 +0200] \"GET /circleci/.env HTTP/1.1\" 404 211 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=IT | ASN: GOOGLE-CLOUD-PLATFORM | Country: IT
show less
Port Scan
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 15:20:02
(30 minutes ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 14:18:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:18:20.638276 2026] [security2:error] [pid 13070:tid 13070] [client 34.154.46.19:43888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angove.biz"] [uri "/.git/config"] [unique_id "ap7HrJuQL6qVeuWrrFWCvAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:26:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:26:19.710652 2026] [security2:error] [pid 22099:tid 22159] [client 34.154.46.19:47016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anglicancommission.com"] [uri "/.git/config"] [unique_id "ap67e-0WQ5tRQZs2LT72XwAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-07 13:11:21
(2 hours ago)
[Mon Sep 07 23:11:20.123925 2026] [security2:error] [pid 102549] [client 34.154.46.19:52028] [client ...
show more
[Mon Sep 07 23:11:20.123925 2026] [security2:error] [pid 102549] [client 34.154.46.19:52028] [client 34.154.46.19] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/"] [unique_id "ap63-LzW4fxvpLpOYu8XeAAAAAU"]
...
show less
Web App Attack
Anonymous
2026-09-07 11:30:47
(4 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.angiotech.gr; logs=/var/log/httpd/domains/angiotech.gr.log ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.angiotech.gr; logs=/var/log/httpd/domains/angiotech.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-07 10:29:29
(5 hours ago)
12.644 requests with url.path *.env
2.193 requests with url.path *phpinfo.php
359 requests with u ...
show more
12.644 requests with url.path *.env
2.193 requests with url.path *phpinfo.php
359 requests with url.path *credentials.json
194 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-07 10:05:02
(5 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-07 09:33:08
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:28:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:28:39.010288 2026] [security2:error] [pid 28865:tid 28865] [client 34.154.46.19:44640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angeltarrac.com"] [uri "/.git/config"] [unique_id "ap6Dx-NW4WuqsfKG8vLiZgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:11:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:11:10.901906 2026] [security2:error] [pid 23433:tid 23433] [client 34.154.46.19:39846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angelsofrhodeisland.com"] [uri "/.git/config"] [unique_id "ap5_rja5EWLuc4YAhttKDgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:23:20
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:23:13.885236 2026] [security2:error] [pid 7799:tid 7799] [client 34.154.46.19:47140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angelpalomino.com"] [uri "/.git/config"] [unique_id "ap50cQfoCG-FjTLNrvGtmgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:07:35
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.46.19 (19.46.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:07:27.777291 2026] [security2:error] [pid 8597:tid 8597] [client 34.154.46.19:55720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angelonearth.net"] [uri "/.git/config"] [unique_id "ap5wvyPlbE9mcg-xPMdRlgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
miszterx.hu
2026-09-07 07:56:47
(7 hours ago)
XORP (haproxy): 73x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 73x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-07 07:32:46
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack