🇬🇧
thetomtaylor.co.uk
2026-09-08 14:08:02
(1 day ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02]
Hacking
SQL Injection
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-08 13:07:02
(1 day ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 12:15:01
(1 day ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
Anonymous
2026-09-08 12:09:30
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 11:37:23
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇦🇺
rubixstudios
2026-09-08 11:23:02
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇫🇷
Zundapper
2026-09-08 11:18:56
(1 day ago)
34.180.69.87 - - [08/Sep/2026:13:18:47 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 117 "- ...
show more
34.180.69.87 - - [08/Sep/2026:13:18:47 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 117 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
34.180.69.87 - - [08/Sep/2026:13:18:47 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 117 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
34.180.69.87 - - [08/Sep/2026:13:18:47 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 117 "-" "Mozilla/5.0 (compatible; facebookexternalhit/1.1; +http://www.facebook.com/externalhit_uatext.php)"
34.180.69.87 - - [08/Sep/2026:13:18:47 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 117 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; LinkedInBot/1.0; +http://www.linkedin.com)"
34.180.69.87 - - [08/Sep/2026:13:18:56 +0200] "GET /@fs/app/terraform.tfstate?raw?? HTTP/1.1" 404 117 "-
...
show less
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-08 11:11:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.69.87 (87.69.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.69.87 (87.69.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:11:17.305976 2026] [security2:error] [pid 3083:tid 3083] [client 34.180.69.87:39444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamlikeitmatters.com"] [uri "/@fs/.env"] [unique_id "ap_tVbCWijAc9h9hpsFEQAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-08 11:11:02
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-08 10:55:10
(1 day ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-09-08 10:39:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.69.87 (87.69.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.69.87 (87.69.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:39:14.188825 2026] [security2:error] [pid 12737:tid 12737] [client 34.180.69.87:63434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.daisydoesoap.com"] [uri "/@fs/root/.env"] [unique_id "ap_l0ormynrvoFjTavdauAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 10:03:52
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 09:20:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.69.87 (87.69.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.69.87 (87.69.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:19:57.677337 2026] [security2:error] [pid 15339:tid 15339] [client 34.180.69.87:5730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.elianabeam.com"] [uri "/@fs/root/.env"] [unique_id "ap_TPdubZUnFlotN9KjygwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-08 09:17:35
(1 day ago)
34.180.69.87 - - [08/Sep/2026:17:17:08 +0800] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 2057 "-" "Moz ...
show more
34.180.69.87 - - [08/Sep/2026:17:17:08 +0800] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 2057 "-" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.7190.79 Mobile Safari/537.36; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user"
34.180.69.87 - - [08/Sep/2026:17:17:08 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 29865 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler) Chrome/85.0.6569.127 Mobile Safari/537.36"
34.180.69.87 - - [08/Sep/2026:17:17:30 +0800] "GET /@fs/../../../../../proc/self/environ?raw?? HTTP/1.1" 400 2589 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.8497.123 Safari/537.36; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
34.180.69.87 - - [08/Sep/2026:17:17:30 +0800] "GET /@fs/../../../../../
...
show less
Brute-Force
🇬🇧
consul.to
2026-09-08 08:33:36
(1 day ago)
Web attack/malicious scanning detected
Web App Attack