🇳🇱
homeshowdomain.nl
2026-08-27 21:59:42
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
🇮🇳
evicky2002
2026-08-27 06:00:33
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-08-27 05:11:56
(2 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 19:21:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:21:28.256018 2026] [security2:error] [pid 11234:tid 11234] [client 34.182.76.63:16472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gisur.com"] [uri "/@fs/../.env"] [unique_id "ao88uBo4g74EkSVx0GOJ8wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Epimetheus
2026-08-26 18:14:32
(3 days ago)
Zombie network / Bot scanner detected:
[GET] /.ssh/id_ed25519
[GET] /config/gcp.json
[GET] /config/ ...
show more
Zombie network / Bot scanner detected:
[GET] /.ssh/id_ed25519
[GET] /config/gcp.json
[GET] /config/database.yml
[GET] /db.sql
[GET] /debug/pprof/
[GET] /application/.env
[GET] /aws/.env.production
[GET] /.ssh/config
[GET] /env-config.js
[GET] /aws/ecs/task-credentials
[GET] /.vercel/.env.development.local
[GET] /debug.log
[GET] /.continue/config.json
[GET] /k8s/eks/credentials
[GET] /vendor/aws/credentials
[GET] /html/.env
[GET] /fetch
[GET] /api/image
[GET] /api/webhook
[GET] /storage/logs/laravel.log
[GET] /@fs/home/ubuntu/.aws/credentials
[GET] /assets/env.js
[GET] /.gitlab-ci.yml
[GET] /read
[GET] /@fs/root/.aws/config
[GET] /env.js
[GET] /aws-exports.js
[GET] /.cursor/mcp.json
[GET] /@fs/proc/1/environ
[GET] /@fs/root/.env
[GET] /.vercel/.env
[GET] /debug/pprof/cmdline
[GET] /@fs/app/.aws/credentials
[GET] /@fs/proc/self/cwd/.aws/credentials
[GET] /.env.development
[GET] /server/.env
[GET] /.env.backup
[GET] /@fs/proc/self/cwd/.env
[GET] /config/.env
[GET] /_nuxt/.
...(Truncated)
show less
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 17:35:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:35:12.709533 2026] [security2:error] [pid 32557:tid 32557] [client 34.182.76.63:51194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southhigh81.com"] [uri "/media../.env"] [unique_id "ao8j0H0VoMo0U2T5bCMRuwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 16:33:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:33:14.395490 2026] [security2:error] [pid 26065:tid 26065] [client 34.182.76.63:18990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.noel-designs.com"] [uri "/.env"] [unique_id "ao8VSsMwd2zfb34Xyn2AqQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
tecnoacquisti.com
2026-08-26 15:39:23
(3 days ago)
PrestaShop Security Module: suspicious probe path detected (/.git)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 13:50:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:50:01.630281 2026] [security2:error] [pid 15051:tid 15051] [client 34.182.76.63:26066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koidivision.com"] [uri "/static../.env"] [unique_id "ao7vCS_gCjgww-13Zi-3CQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 13:39:40
(3 days ago)
Aggressive web scan
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-26 13:39:39
(3 days ago)
[Wed Aug 26 23:39:38.697696 2026] [security2:error] [pid 355574] [client 34.182.76.63:1284] [client ...
show more
[Wed Aug 26 23:39:38.697696 2026] [security2:error] [pid 355574] [client 34.182.76.63:1284] [client 34.182.76.63] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.co.nz"] [uri "/.git/HEAD"] [unique_id "ao7smkLmkHiafl5CWCt9rwAAAAY"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 13:23:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.76.63 (63.76.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:23:43.347590 2026] [security2:error] [pid 22644:tid 22662] [client 34.182.76.63:47994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accushot.com"] [uri "/@fs/../.env"] [unique_id "ao7o31V6fmkkhsxb7tM_lQAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-08-26 11:42:19
(3 days ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
ConsulHosting
2026-08-26 10:29:24
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇳🇿
Tripwire
2026-08-26 09:33:59
(3 days ago)
Scanning for exploits - /static../.aws/credentials
Hacking
Web App Attack