๐ช๐ธ
pipeline.es
2026-10-08 18:52:21
(24 minutes ago)
Web scanning / probing for vulnerable paths | URL: /config/gcp-credentials.json | Evidence: volandov ...
show more
Web scanning / probing for vulnerable paths | URL: /config/gcp-credentials.json | Evidence: volandoviajes.com.mx 34.90.56.53 - - [08/Oct/2026:20:50:48 +0200] \"GET /config/gcp-credentials.json HTTP/2.0\" 404 31658 \"-\" \"Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)\" GEOIP_COUNTRY_CODE=NL 32344 | ASN: GOOGLE-CLOUD-PLATFORM | Country: NL
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 18:23:59
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:23:53.101969 2026] [security2:error] [pid 30178:tid 30178] [client 34.90.56.53:57590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiofamilia.com.mx"] [uri "/files../.env"] [unique_id "asffuWn40R17HygX6UudbwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-10-08 18:16:51
(59 minutes ago)
tcp/443; PHP-CGI argument injection exploit attempt (CVE-2012-1823 / CVE-2024-4577) forcing auto_pre ...
show more
tcp/443; PHP-CGI argument injection exploit attempt (CVE-2012-1823 / CVE-2024-4577) forcing auto_prepend_file to php://input for remote code execution, lowercase-hex variant sent to /index.php, /cgi-bin/php and /php-cgi/php-cgi.exe: "POST /index.php?%ADd+
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-08 18:02:07
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
OK
2026-10-08 17:58:03
(1 hour ago)
HTTP/HTTPS
Hacking
Web App Attack
๐บ๐ธ
dtorrer
2026-10-08 17:55:17
(1 hour ago)
General vulnerability scan.
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 17:54:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:54:32.071438 2026] [security2:error] [pid 10671:tid 10671] [client 34.90.56.53:56612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juca.com.mx"] [uri "/.htpasswd"] [unique_id "asfY2O4mPX33cKoLbppUwQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 17:14:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 13:14:33.939339 2026] [security2:error] [pid 26891:tid 26891] [client 34.90.56.53:60434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elpais.mx"] [uri "/.htpasswd"] [unique_id "asfPeX0JNHl7v55wwNjIlAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Omar Martรญnez
2026-10-08 17:14:39
(2 hours ago)
[Thu Oct 08 11:14:27.747099 2026] [core:error] [pid 539929:tid 139843069195840] [remote 34.90.56.53: ...
show more
[Thu Oct 08 11:14:27.747099 2026] [core:error] [pid 539929:tid 139843069195840] [remote 34.90.56.53:34496] AH10244: invalid URI path (/public/plugins/text/../../../../../../../../proc/self/environ)
[Thu Oct 08 11:14:37.616242 2026] [core:error] [pid 539929:tid 139843060786752] [remote 34.90.56.53:34496] AH10244: invalid URI path (/%2e%2e/.env)
...
show less
Phishing
Email Spam
Blog Spam
๐ฉ๐ช
rzk
2026-10-08 17:00:07
(2 hours ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show more
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: GOOGLE-CLOUD-PLATFORM. Country: NL. Timestamp: 2026-10-08T17:00:07+00:00.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:21:21
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.56.53 (53.56.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:21:14.139146 2026] [security2:error] [pid 25625:tid 25625] [client 34.90.56.53:42646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "animatuevento.com.mx"] [uri "/.htpasswd"] [unique_id "asfC-kRFuL2n_t-88MhSEwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 16:20:36
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
masterguru
2026-10-08 16:19:04
(2 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "applebot" at REQUEST_HEADERS:User-Agent. (1100000-1 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "applebot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
Anonymous
2026-10-08 16:09:06
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection