๐ณ๐ฑ
homeshowdomain.nl
2026-09-09 21:59:04
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-08.
show less
Web App Attack
SSH
Hacking
๐ฎ๐ณ
evicky2002
2026-09-09 00:01:20
(3 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
dot.mg
2026-09-08 12:08:03
(3 weeks ago)
Bad behaviour
Web Spam
๐ณ๐ฑ
MyGlobalFlowers
2026-09-08 11:47:57
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 10:43:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:42:58.081944 2026] [security2:error] [pid 15114:tid 15114] [client 34.187.34.255:42014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.purlandpurr.leadek.com"] [uri "/@fs/.env"] [unique_id "ap_mshrlIKpWLT4qYmWBuQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-09-08 10:31:06
(3 weeks ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 10:02:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:01:56.497752 2026] [security2:error] [pid 31053:tid 31053] [client 34.187.34.255:20664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bowerwood.com"] [uri "/@fs/.env"] [unique_id "ap_dFLRGeLCi_B1_kuFyawAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 08:24:39
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:24:33.625654 2026] [security2:error] [pid 22396:tid 22396] [client 34.187.34.255:19652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forwardfusion.co"] [uri "/@fs/src/.env"] [unique_id "ap_GQZObguq9YBGztCzzzgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
zumbo.net
2026-09-08 07:10:36
(3 weeks ago)
[Tue Sep 08 10:08:54.751387 2026] [proxy_fcgi:error] [pid 247026:tid 247041] [client 34.187.34.255:0 ...
show more
[Tue Sep 08 10:08:54.751387 2026] [proxy_fcgi:error] [pid 247026:tid 247041] [client 34.187.34.255:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 08 10:08:59.971645 2026] [proxy_fcgi:error] [pid 247026:tid 247069] [client 34.187.34.255:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 08 10:09:09.952383 2026] [proxy_fcgi:error] [pid 247024:tid 247059] [client 34.187.34.255:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 08 10:09:09.959058 2026] [proxy_fcgi:error] [pid 247026:tid 247076] [client 34.187.34.255:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 08 10:10:35.242945 2026] [proxy_fcgi:error] [pid 247024:tid 247039] [client 34.187.34.255:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-08 06:47:20
(3 weeks ago)
34.187.34.255 - - [08/Sep/2026:08:46:18 +0200] "GET HTTP/1.1" 403 764 "-" "Mozilla/5.0 (Linux; Andr ...
show more
34.187.34.255 - - [08/Sep/2026:08:46:18 +0200] "GET HTTP/1.1" 403 764 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot) Chrome/134.0.3193.235 Mobile Safari/537.36"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-08 06:25:03
(3 weeks ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 05:47:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.34.255 (255.34.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:47:31.663550 2026] [security2:error] [pid 5524:tid 5524] [client 34.187.34.255:24154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tekrav.com"] [uri "/@fs/.env"] [unique_id "ap-hc8xCBdhGkR-PHZkUfwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-08 05:40:23
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
cmbplf
2026-09-08 05:36:01
(3 weeks ago)
1.008 requests with url.path *config.json
946 requests with url.path *credentials.json
584 reques ...
show more
1.008 requests with url.path *config.json
946 requests with url.path *credentials.json
584 requests with url.path *.azure/*
216 requests with url.path */auth.json
121 requests with url.path *.local/share/*
show less
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-08 05:24:55
(3 weeks ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack