🇧🇪
cmbplf
2026-09-08 15:05:15
(22 hours ago)
1.100 requests with url.path *phpinfo.php
102 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 12:05:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.42.90 (90.42.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.42.90 (90.42.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:05:39.990883 2026] [security2:error] [pid 31469:tid 31469] [client 34.22.42.90:43212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jemsfood.com"] [uri "/.git/config"] [unique_id "ap_6E8QEH4cCrKxx0mnb6QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 11:59:00
(1 day ago)
Multiple WAF Violations
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-08 11:44:15
(1 day ago)
(php_susp_dir) srv104 PHP Suspicious Directory 34.22.42.90 (US/United States/90.42.22.34.bc.googleus ...
show more
(php_susp_dir) srv104 PHP Suspicious Directory 34.22.42.90 (US/United States/90.42.22.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇪🇸
pipeline.es
2026-09-08 11:18:00
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.sample | Evidence: jelouuholidays.com 34.22 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.sample | Evidence: jelouuholidays.com 34.22.42.90 - - [08/Sep/2026:13:17:05 +0200] \"GET /.env.sample HTTP/1.1\" 404 33408 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇳🇱
Site.eu
2026-09-08 10:35:05
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
Mangelot Hosting
2026-09-08 10:26:21
(1 day ago)
(php_susp_dir) srv103 PHP Suspicious Directory 34.22.42.90 (US/United States/90.42.22.34.bc.googleus ...
show more
(php_susp_dir) srv103 PHP Suspicious Directory 34.22.42.90 (US/United States/90.42.22.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇫🇷
Octopuce
2026-09-08 10:12:42
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇮🇹
VHosting
2026-09-08 08:55:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
middelkoopcc
2026-09-08 07:29:01
(1 day ago)
2026-09-08 09:23:34 GET /.git/config [404] && 2026-09-08 09:23:38 GET /.env [404] && 2026-09-08 09:2 ...
show more
2026-09-08 09:23:34 GET /.git/config [404] && 2026-09-08 09:23:38 GET /.env [404] && 2026-09-08 09:23:53 GET /.env.bak [404] && 117 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:12:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.42.90 (90.42.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.42.90 (90.42.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:12:22.930549 2026] [security2:error] [pid 24238:tid 24238] [client 34.22.42.90:51890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffreycopeland.com"] [uri "/.git/config"] [unique_id "ap-1VkLd0c6gxuTCu68xPAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:53:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.22.42.90 (90.42.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.42.90 (90.42.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:53:38.274817 2026] [security2:error] [pid 26447:tid 26447] [client 34.22.42.90:58952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffmasonmusic.com"] [uri "/.git/config"] [unique_id "ap-w8s-0HlyECzkBVVCUqQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack