Anonymous
2026-09-29 08:00:10
(1 week ago)
Bot / scanning and/or hacking attempts: POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_fi ...
show more
Bot / scanning and/or hacking attempts: POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%, POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e, GET / HTTP/2.0, [117/117] done: stream 265, GET /dist../.env, POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend, POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_fil
show less
Hacking
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-29 05:31:53
(1 week ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 11. First blocked: 2026-09-29.
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-27 14:54:24
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:58:38
(2 weeks ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 16:30:18
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /app-config.json | Evidence: microsites.grupoeuro ...
show more
Web scanning / probing for vulnerable paths | URL: /app-config.json | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:18:28:15 +0200] \"GET /app-config.json HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 16:11:09
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /service-account.json | Evidence: microsites.grup ...
show more
Web scanning / probing for vulnerable paths | URL: /service-account.json | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:18:10:11 +0200] \"GET /service-account.json HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 15:50:54
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /.bashrc | Evidence: microsites.grupoeuropa.com 3 ...
show more
Web scanning / probing for vulnerable paths | URL: /.bashrc | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:17:49:04 +0200] \"GET /.bashrc HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 15:25:44
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /firebase-service-account.json | Evidence: micros ...
show more
Web scanning / probing for vulnerable paths | URL: /firebase-service-account.json | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:17:24:07 +0200] \"GET /firebase-service-account.json HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 15:07:34
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /__debug__/ | Evidence: microsites.grupoeuropa.co ...
show more
Web scanning / probing for vulnerable paths | URL: /__debug__/ | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:17:06:46 +0200] \"GET /__debug__/ HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 14:35:44
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /app_dev.php/_profiler | Evidence: microsites.gru ...
show more
Web scanning / probing for vulnerable paths | URL: /app_dev.php/_profiler | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:16:34:54 +0200] \"GET /app_dev.php/_profiler HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 14:01:11
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /api%2F.env | Evidence: microsites.grupoeuropa.co ...
show more
Web scanning / probing for vulnerable paths | URL: /api%2F.env | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:15:47:42 +0200] \"GET /api%2F.env HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 13:40:47
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /swagger.json | Evidence: microsites.grupoeuropa. ...
show more
Web scanning / probing for vulnerable paths | URL: /swagger.json | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:15:39:05 +0200] \"GET /swagger.json HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 13:30:41
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 13:23:12
(2 weeks ago)
Web scanning / probing for vulnerable paths | URL: /.env.example | Evidence: microsites.grupoeuropa. ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.example | Evidence: microsites.grupoeuropa.com 34.39.209.93 - - [23/Sep/2026:15:22:07 +0200] \"GET /.env.example HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:14:00
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.39.209.93 (93.209.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.39.209.93 (93.209.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:13:55.968395 2026] [security2:error] [pid 9601:tid 9601] [client 34.39.209.93:35446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||7319atwood.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "7319atwood.com"] [uri "/z9x8c7v6b5-debug-trigger-7319atwood.com"] [unique_id "arPCgwKpyx4nE5rmroUeKgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack