🇧🇾
lns.bz
2026-09-09 04:37:05
(5 hours ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
Site.eu
2026-09-09 03:49:31
(6 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
Philister11
2026-09-08 02:38:20
(1 day ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (KR/AS396982)
Web App Attack
Hacking
🇧🇷
Serra Threat Intelligence
2026-09-07 23:51:00
(1 day ago)
Automated vulnerability scanner and exploitation tool hosted on Google Cloud Compute Engine
(Seoul ...
show more
Automated vulnerability scanner and exploitation tool hosted on Google Cloud Compute Engine
(Seoul, KR). Executes high-velocity enumeration (292 requests in ~121 seconds) targeting exposed
.env files, cloud credential JSON files (firebase-key.json, gcp-sa.json, gcp-key.json), phpinfo.php variants,
and .git/config across multiple path permutations. Additionally, attempts active React Remote Code Execution
(RCE) exploitation via POST requests (CVE-2025-55182).* last_seen: 2026-09-07 14:13:07 UTC
* volume: 292 requests in ~121 seconds (~2.4 req/sec); Recursive Environment Variable Scanning (.env in Subdirectories): Systematic GET requests targeting sensitive configuration files hidden across framework-specific paths (e.g., /.env, /mongodb/.env, /travis/.env, /.git/.env, /laravel5/.env).
Cloud Keys & Credentials Harvesting (GCP / Firebase): Targeted bursts aiming to discover exposed service account credentials and keys (/firebase-key.json, /keyfile.json).
show less
Bad Web Bot
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 13:19:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:19:00.321550 2026] [security2:error] [pid 16264:tid 16264] [client 34.47.82.166:53528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "richardpetersbooks.easyweb-publishing.com"] [uri "/.env.local"] [unique_id "ap65xPpEK9HsyugW2yXWvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 12:37:59
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:18:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:18:33.434305 2026] [security2:error] [pid 12561:tid 12561] [client 34.47.82.166:46372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "richsilver.com"] [uri "/.git/config"] [unique_id "ap6diRro5bgmf90jLaj9VwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:23:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:23:12.986927 2026] [security2:error] [pid 11242:tid 11242] [client 34.47.82.166:39308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "richobservatory.com"] [uri "/.git/config"] [unique_id "ap6QkPaCAPSswjL5-NfB4AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:05:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:05:50.756065 2026] [security2:error] [pid 9834:tid 9834] [client 34.47.82.166:48272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "richmondrents.com"] [uri "/.git/config"] [unique_id "ap6MfvLlRKuwtT_BDVpMOQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 08:46:08
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇩🇪
paissangroup
2026-09-07 07:48:57
(2 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:47:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:47:41.293082 2026] [security2:error] [pid 13125:tid 13125] [client 34.47.82.166:57214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riccibuilders.net"] [uri "/.git/config"] [unique_id "ap5sHUF2O8Cf7DnEfEvXNAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:12:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.82.166 (166.82.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:12:28.886402 2026] [security2:error] [pid 30807:tid 30807] [client 34.47.82.166:47040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riccardiagency.com"] [uri "/.git/config"] [unique_id "ap5j3IEf_2CWF3VMeBaxNQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
palla89
2026-09-07 06:24:11
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.47.82.166 (KR/South Korea/166.82.47. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.47.82.166 (KR/South Korea/166.82.47.34.bc.googleusercontent.com)
show less
SQL Injection
🇦🇺
rubixstudios
2026-09-07 05:18:02
(2 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack