Anonymous
2026-09-11 19:45:11
(5 hours ago)
Bot / seems abusive / Apache connections: 23
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-09-11 19:39:25
(5 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-11 19:27:47
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.182.72.254 (US/United States/254.72. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.182.72.254 (US/United States/254.72.182.34.bc.googleusercontent.com)
show less
SQL Injection
🇬🇧
consul.to
2026-09-11 18:42:03
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
masterguru
2026-09-11 15:10:19
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇩🇪
LRob
2026-09-11 13:54:43
(10 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-11 13:54 UTC
show less
Hacking
Web App Attack
🇺🇸
WizardsToolkit
2026-09-11 13:36:35
(11 hours ago)
tried to access forbidden files; attempted to access /app/.env
Web App Attack
🇫🇷
Catalin Negru
2026-09-11 12:27:39
(12 hours ago)
2026-09-11 15:27:38,369 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 34.182.72.254
...
show more
2026-09-11 15:27:38,369 fail2ban.actions [1796604]: NOTICE [laravel-auth] Ban 34.182.72.254
2026-09-11 15:27:38,413 fail2ban.actions [1796604]: NOTICE [apache-dirscan] Ban 34.182.72.254
2026-09-11 15:27:38,504 fail2ban.actions [1796604]: NOTICE [web-scanner] Ban 34.182.72.254
2026-09-11 15:27:38,630 fail2ban.actions [1796604]: NOTICE [laravel-env] Ban 34.182.72.254
2026-09-11 15:27:38,722 fail2ban.actions [1796604]: NOTICE [apache-scan] Ban 34.182.72.254
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 11:59:01
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:58:57.556975 2026] [security2:error] [pid 5232:tid 5232] [client 34.182.72.254:58422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intelligencer.us"] [uri "/.git/config"] [unique_id "aqPtAbJ4vBz7vvNH7ezhgQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 10:04:39
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:04:35.449004 2026] [security2:error] [pid 25208:tid 25208] [client 34.182.72.254:53398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intelerium.com"] [uri "/.git/config"] [unique_id "aqPSM20G9X9fbh_1hNqWAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 08:53:51
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 04:53:45.549871 2026] [security2:error] [pid 12368:tid 12368] [client 34.182.72.254:55004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integritysecurity.integritysecurity.us"] [uri "/.git/config"] [unique_id "aqPBmR-i8DVcSoCu25za7gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-11 08:44:30
(16 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇨🇭
🇨🇭 Hosting
2026-09-11 05:10:34
(19 hours ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:05:07
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.72.254 (254.72.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:05:03.338316 2026] [security2:error] [pid 13280:tid 13280] [client 34.182.72.254:42160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integratic.com.co"] [uri "/.git/config"] [unique_id "aqOL_1XbzkVWk2n0ZGknrgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
pixiekat
2026-09-11 03:59:48
(20 hours ago)
[Fri Sep 11 04:59:47.071894 2026] [security2:error] [pid 3689055:tid 3689142] [client 34.182.72.254: ...
show more
[Fri Sep 11 04:59:47.071894 2026] [security2:error] [pid 3689055:tid 3689142] [client 34.182.72.254:44766] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "integraldata.cc"] [uri "/"] [unique_id "aqN8s4P_4tJiCZiN3jEiBAAAAAY"]
[Fri Sep 11 04:59:47.631496 2026] [security2:error] [pid 3689056:tid 3689165] [client 34.182.72.254:44776] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "integraldata.cc"] [uri "/"] [unique_id "aqN8s-QYqeMn262Zih1KHwAAAFQ"]
[Fri Sep 11 04:59:48.178441 2026]
...
show less
Web App Attack