๐ณ๐ฑ
larse99
2026-09-17 12:03:17
(17 hours ago)
Detected Scanning / Hacking activity
Port Scan
Hacking
๐ง๐ท
dermatovirtual
2026-09-17 11:35:29
(17 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 199 unauthorized requests recorded between 2026-09-17 08:40:54 UTC and 2026-09-17 08:41:52 UTC (rate: ~199 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 08:41:51 UTC] IP: 34.78.136.180 - W3C IIS (Port 443): GET /uat/.env -> HTTP 404 [CLIENT: 34.78.136.180]
[2026-09-17 08:41:52 UTC] IP: 34.78.136.180 - W3C IIS (Port 443): GET /production/.env -> HTTP 404 [CLIENT: 34.78.136.180]
[2026-09-17 08:41:52 UTC] IP: 34.78.136.180 - W3C IIS (Port 443): GET /stage/.env -> HTTP 404 [CLIENT: 34.78.136.180]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-17 10:08:01
(19 hours ago)
2026-09-17 12:06:27 GET /.git/config [404] && 2026-09-17 12:06:28 GET /.env [404] && 2026-09-17 12:0 ...
show more
2026-09-17 12:06:27 GET /.git/config [404] && 2026-09-17 12:06:28 GET /.env [404] && 2026-09-17 12:06:29 GET /.env.bak [404] && 150 more within 20 minutes
show less
Web App Attack
Anonymous
2026-09-17 08:30:02
(20 hours ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:00:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:00:48.737086 2026] [security2:error] [pid 9650:tid 9650] [client 34.78.136.180:44762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "testsite.etudesoftware.com"] [uri "/.git/config"] [unique_id "aqtl8Fz55_aWLh6-_6LrwgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 03:57:52
(1 day ago)
[ti-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.78.136.180 - - [17/Sep/2026:05:57:34 +0200] "GET /.git/config HTTP/1.1" 404 2105 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-17 03:28:53
(1 day ago)
URL Probing: /server/.env
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-17 03:25:17
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.78.136.180 (BE/Belgium/180.136.78.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.78.136.180 (BE/Belgium/180.136.78.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-16 19:28:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:28:01.283649 2026] [security2:error] [pid 19549:tid 19549] [client 34.78.136.180:40438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stagemadrid.com"] [uri "/.git/config"] [unique_id "aqrtwY20aJuNCkbu85BwJgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 18:50:03
(1 day ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:08:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:07:55.175994 2026] [security2:error] [pid 4848:tid 4848] [client 34.78.136.180:58222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stage.dtla2028.com"] [uri "/.git/config"] [unique_id "aqq-2zkWZFFjbZTSgJt5ygAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 12:46:25
(1 day ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:53:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:53:25.734098 2026] [security2:error] [pid 25365:tid 25365] [client 34.78.136.180:36302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "statevictoryfund.progressivefileshare.org"] [uri "/.git/config"] [unique_id "aqm-VSpqr55-YqRFx1cp8AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-15 21:22:08
(2 days ago)
CMS/framework probe: 34.78.136.180 - - [15/Sep/2026:23:22:08 +0200] "GET /.git/config HTTP/1.1" 444 ...
show more
CMS/framework probe: 34.78.136.180 - - [15/Sep/2026:23:22:08 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" asn=396982 org="Google LLC" country=BE
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:03:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.136.180 (180.136.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:03:53.427675 2026] [security2:error] [pid 10143:tid 10164] [client 34.78.136.180:57992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stateabbreviationlist.com"] [uri "/.git/config"] [unique_id "aqmkqcV4yunqWwklqDpjAQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack