🇩🇪
Hazzard
2026-09-08 20:10:20
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇬🇧
NotCool
2026-09-08 20:04:02
(4 hours ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.83.175.181 (US/United States/181.175.83.34.bc.goog ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.83.175.181 (US/United States/181.175.83.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
🇿🇦
conure.sh
2026-09-08 19:41:46
(4 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 6s
Web App Attack
🇬🇧
consul.to
2026-09-08 18:57:57
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:56:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:56:05.136504 2026] [security2:error] [pid 19044:tid 19044] [client 34.83.175.181:11800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.remedialconcepts.banis-associates.com"] [uri "/@fs/.env"] [unique_id "aqBaRULzBQoewY-eFhAu0AAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:21:22
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:21:14.722028 2026] [security2:error] [pid 10243:tid 10243] [client 34.83.175.181:16284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rxrepconnect.circlehealthcaregroup.com"] [uri "/@fs/app/.env"] [unique_id "aqBSGrjN7VhonruDgKG_FwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-08 18:13:23
(6 hours ago)
Web scanning / probing for vulnerable paths | URL: /env.json | Evidence: microsites.grupoeuropa.com ...
show more
Web scanning / probing for vulnerable paths | URL: /env.json | Evidence: microsites.grupoeuropa.com 34.83.175.181 - - [08/Sep/2026:20:12:20 +0200] \"GET /env.json HTTP/1.1\" 404 4216 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇫🇷
dynamix
2026-09-08 18:06:57
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
mnsf
2026-09-08 18:05:58
(6 hours ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-08 17:48:03
(6 hours ago)
159 requests with url.path */auth.json
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 17:28:59
(6 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:11:45
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:11:40.248132 2026] [security2:error] [pid 16833:tid 16833] [client 34.83.175.181:5434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.enespiral.net"] [uri "/@fs/app/.env"] [unique_id "aqBBzDTbNvapXoMR1CClPwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:55:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:54:56.643917 2026] [security2:error] [pid 4606:tid 4606] [client 34.83.175.181:12074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.funkerecords.com"] [uri "/@fs/app/.env"] [unique_id "aqA94BbTVGEgm6O3gCuhGAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:33:35
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.175.181 (181.175.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:33:27.917456 2026] [security2:error] [pid 22371:tid 22371] [client 34.83.175.181:60796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.waggonerfinancial.com"] [uri "/@fs/.env"] [unique_id "aqA41wZv2in6_MEGv9DgiwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-08 16:25:21
(7 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking