🇺🇸
TPI-Abuse
2026-09-06 19:53:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.41.76.77 (77.76.41.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.41.76.77 (77.76.41.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:53:38.461309 2026] [security2:error] [pid 3693:tid 3706] [client 34.41.76.77:42774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prominentregroup.com"] [uri "/.git/config"] [unique_id "ap3EwuAluAXxkD5NZRaVWQAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yvoictra
2026-09-06 18:31:32
(4 hours ago)
Bloqueado automáticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
🇫🇮
mnazibo
2026-09-06 18:00:05
(5 hours ago)
Date: 06/Sep/2026 20:33:09 | Reported IP: 34.41.76.77 mod_security | id: 930130 932130 932235 932260 ...
show more
Date: 06/Sep/2026 20:33:09 | Reported IP: 34.41.76.77 mod_security | id: 930130 932130 932235 932260 933135 934100 934130 942151 942550 | US/group.my_domain/- | Connections: 252 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /actions/.env; /admin/.env; /administrator/.env; /administrator/phpinfo.php; /admin-panel/.env; /admin/phpinfo.php; /angular/.env; /ansible/.env; /api/dev/.env; /api/.env; /api/staging/.env; /api/v1/.env; /api/v2/.env; /api/v3/.env; /app/.env; /application_default_credentials.json; /application/.env; /apps/.env; /aws/.env; /azure/.env; /backend/.env; /backup/.env; /backups/.env; /beta/.env; /beta/phpinfo.php; /bin/.env; /bootstrap/.env; /brevo/.env; /build/.env; /buildkite/.env; /bulk/.env; /cache/.env; /cakephp/.env; /campaign/.env; /cd/.env; /ci/.env; /circleci/.env; /classic/graph; /client/.env; /cloud/.env; /cms/.env; /codeigniter/.env; /config/app/.env; /config/.env; /.config/gcloud/application_default_credent
show less
SQL Injection
Brute-Force
Bad Web Bot
Anonymous
2026-09-06 17:34:06
(5 hours ago)
Scanner hitting /.git/config on prometheus.picsou.cloud (GOOGL-2) — aaguard
Brute-Force
Port Scan
🇪🇸
yvoictra
2026-09-06 17:08:48
(5 hours ago)
34.41.76.77 - - [06/Sep/2026:19:08:46 +0200] "GET /.git/config HTTP/1.1" 404 19 "-" "Mozilla/5.0 (X1 ...
show more
34.41.76.77 - - [06/Sep/2026:19:08:46 +0200] "GET /.git/config HTTP/1.1" 404 19 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.41.76.77 - - [06/Sep/2026:19:08:47 +0200] "GET /.env HTTP/1.1" 404 19 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.41.76.77 - - [06/Sep/2026:19:08:47 +0200] "GET /.env.local HTTP/1.1" 404 19 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.41.76.77 - - [06/Sep/2026:19:08:47 +0200] "GET /.env.production HTTP/1.1" 404 19 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.41.76.77 - - [06/Sep/2026:19:08:47 +0200] "GET /.env.staging HTTP/1.1" 404 19 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇫🇮
mnazibo
2026-09-06 17:00:32
(6 hours ago)
Date: Sep 06 19:05:11 2026 EAT | Reported IP: 34.41.76.77 mod_security | id: 932130 932235 932260 93 ...
show more
Date: Sep 06 19:05:11 2026 EAT | Reported IP: 34.41.76.77 mod_security | id: 932130 932235 932260 933135 934100 934130 942151 942550 949110 930130 920440 920500 | US/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Direct Unix Command Execution; Remote Command Execution: Direct Unix Command Execution; PHP Injection Attack: Variable Access Found; PHP Injection Attack: Variable Access Found; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection Attack 1/2; Node.js Injection
show less
SQL Injection
Brute-Force
Bad Web Bot
🇨🇦
Sakusen
2026-09-06 16:50:18
(6 hours ago)
Automated web attack: 277 reqs, 267 paths probed, 232 returned 404; probed: 206 .env, 44 .php, 9 .js ...
show more
Automated web attack: 277 reqs, 267 paths probed, 232 returned 404; probed: 206 .env, 44 .php, 9 .json, 4 secret, 2 other, 1 .git, 1 cloud-cred
show less
Hacking
Bad Web Bot
Web App Attack
🇪🇸
Francisco Vallejo
2026-09-06 16:17:53
(6 hours ago)
[Sun Sep 06 18:17:52.607433 2026] [authz_core:error] [pid 2571398:tid 125405553993408] [client 34.41 ...
show more
[Sun Sep 06 18:17:52.607433 2026] [authz_core:error] [pid 2571398:tid 125405553993408] [client 34.41.76.77:42672] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Sun Sep 06 18:17:52.726997 2026] [authz_core:error] [pid 2571398:tid 125406510302912] [client 34.41.76.77:42672] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Sun Sep 06 18:17:52.879633 2026] [authz_core:error] [pid 2571398:tid 125406787131072] [client 34.41.76.77:42672] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Sun Sep 06 18:17:53.008557 2026] [authz_core:error] [pid 2571398:tid 125406527088320] [client 34.41.76.77:42672] AH01630: client denied by server configuration: proxy:https://localhost:9090/
[Sun Sep 06 18:17:53.209175 2026] [authz_core:error] [pid 2571398:tid 125406795523776] [client 34.41.76.77:42672] AH01630: client denied by server configuration: proxy:https://localhost:9090/.git/config
...
show less
Brute-Force
SSH
🇵🇱
Budyn
2026-09-06 15:23:36
(7 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: prometheus.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 14:15:04
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack