🇪🇸
pipeline.es
2026-09-07 20:49:10
(6 hours ago)
Web scanning / probing for vulnerable paths | URL: /@fs/usr/src/app/.env?raw?? | Evidence: microsite ...
show more
Web scanning / probing for vulnerable paths | URL: /@fs/usr/src/app/.env?raw?? | Evidence: microsites.grupoeuropa.com 8.229.125.142 - - [07/Sep/2026:22:47:50 +0200] \"GET /@fs/usr/src/app/.env?raw?? HTTP/1.1\" 404 - \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
Anonymous
2026-09-07 20:38:24
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇨🇭
backslash
2026-09-07 20:27:00
(7 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇳🇱
Site.eu
2026-09-07 20:10:28
(7 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 20:04:31
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:04:26.094700 2026] [security2:error] [pid 29787:tid 29787] [client 8.229.125.142:47616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyclingboardgames.net.ankitoner.com"] [uri "/@fs/../../.env"] [unique_id "ap8YysSDbJeGFVplqYTjxQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
middelkoopcc
2026-09-07 19:48:01
(7 hours ago)
2026-09-07 21:45:07 GET /@fs/.env?raw?? [404] && 2026-09-07 21:45:07 GET /@fs/proc/self/environ?raw? ...
show more
2026-09-07 21:45:07 GET /@fs/.env?raw?? [404] && 2026-09-07 21:45:07 GET /@fs/proc/self/environ?raw?? [404] && 2026-09-07 21:45:07 GET /@fs/root/.env?raw?? [404] && 122 more within 20 minutes
show less
Web App Attack
🇧🇪
cmbplf
2026-09-07 19:06:17
(8 hours ago)
223 requests with url.path *.config/*
Brute-Force
Bad Web Bot
🇳🇱
svr
2026-09-07 18:40:21
(8 hours ago)
Abusive Automated Web Scanner
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:35:57
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 8.229.125.142 (142.125.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 8.229.125.142 (142.125.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:35:51.901251 2026] [security2:error] [pid 32178:tid 32178] [client 8.229.125.142:7054] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 20)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.joycepelham.com"] [uri "/@fs/..%2f..%2f..%2f..%2f..%2froot/.env"] [unique_id "ap8EB7edGkRp44yQXJV_KgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:19:28
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:19:20.244083 2026] [security2:error] [pid 16702:tid 16702] [client 8.229.125.142:65060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hakanbasboga.com"] [uri "/@fs/.env"] [unique_id "ap8AKFngXllwXNJeiTzniwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
wlt-blocker
2026-09-07 18:06:37
(9 hours ago)
Unauthorized access to webpage admin
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:17:11
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:17:04.545498 2026] [security2:error] [pid 19432:tid 19432] [client 8.229.125.142:47942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.terrybeachmusic.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap7xkLqhfS-LHNn09VcNigAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇱
router.al
2026-09-07 17:05:27
(10 hours ago)
09/07/2026-17:05:26.767287 8.229.125.142 Protocol: 6 ET EXPLOIT VMware Spring Cloud Directory Traver ...
show more
09/07/2026-17:05:26.767287 8.229.125.142 Protocol: 6 ET EXPLOIT VMware Spring Cloud Directory Traversal (CVE-2020-5410)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-07 16:35:08
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.125.142 (142.125.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:35:04.907084 2026] [security2:error] [pid 28514:tid 28514] [client 8.229.125.142:33710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.eaglesnestbandb.com"] [uri "/@fs/../../.env"] [unique_id "ap7nuM2WIOcR2382WfIXqQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 15:45:03
(11 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack