๐บ๐ธ
TPI-Abuse
2026-09-19 18:22:40
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:22:34.642959 2026] [security2:error] [pid 18642:tid 18642] [client 187.127.129.131:43718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joescherzi.com"] [uri "/.env.txt"] [unique_id "aq7S6uxRTHDHT8B0BvVb-gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-19 18:22:11
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 17:19:59
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:19:54.159699 2026] [security2:error] [pid 31244:tid 31244] [client 187.127.129.131:55478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atheismz.com"] [uri "/.env.txt"] [unique_id "aq7EOtHb5fYIApNCPw99nQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 16:43:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 12:43:27.406741 2026] [security2:error] [pid 21604:tid 21604] [client 187.127.129.131:59066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zazuza.com"] [uri "/.env.txt"] [unique_id "aq67rwtuGoN-W3Ykmo3lsAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-19 07:41:08
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-19 07:37:21
(14 hours ago)
(caddyscan) Scanner path probe from 187.127.129.131 (IN/India/srv1488650.hstgr.cloud): 5 in the last ...
show more
(caddyscan) Scanner path probe from 187.127.129.131 (IN/India/srv1488650.hstgr.cloud): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 187.127.129.131 - - [19/Sep/2026:07:37:17 +0000] "GET /.env.txt HTTP/1.1"
[REDACTED] 200 2627 187.127.129.131 - - [19/Sep/2026:07:37:17 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 187.127.129.131 - - [19/Sep/2026:07:37:18 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 187.127.129.131 - - [19/Sep/2026:07:37:18 +0000] "GET /.git/index HTTP/1.1"
[REDACTED] 200 2627 187.127.129.131 - - [19/Sep/2026:07:37:18 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 06:20:01
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 02:19:53.755888 2026] [security2:error] [pid 8509:tid 8509] [client 187.127.129.131:41654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.topfer.toepfer.org"] [uri "/.git/config"] [unique_id "aq4piVoG-VXLP-Rk_3vEAgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 22:37:50
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 18:37:45.731548 2026] [security2:error] [pid 29311:tid 29311] [client 187.127.129.131:37264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desarrollosdecolima.imerka.com.mx"] [uri "/.env.backup"] [unique_id "aq29OdfzPc81_nHmg6x_AQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-18 14:32:58
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 03:03:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 23:03:09.614771 2026] [security2:error] [pid 5780:tid 5780] [client 187.127.129.131:37242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handcraftedparquet.com"] [uri "/.git/index"] [unique_id "aqyp7RD5xLC6z7A7_OLKHAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 02:37:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:37:28.618497 2026] [security2:error] [pid 5747:tid 5747] [client 187.127.129.131:57090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rhfandsfpquestions.daisydoesoap.com"] [uri "/.env.local"] [unique_id "aqyj6NtF9hZ-jdeS2qKcuwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-17 22:00:05
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-17
Web App Attack
SSH
Hacking
๐ธ๐ช
vaia.cloud
2026-09-17 21:35:02
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-17 09:52:10
(2 days ago)
[17/Sep/2026:12:52:10 +0300] -- 187.127.129.131 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp ...
show more
[17/Sep/2026:12:52:10 +0300] -- 187.127.129.131 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 08:20:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 187.127.129.131 (srv1488650.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:20:05.313521 2026] [security2:error] [pid 8014:tid 8014] [client 187.127.129.131:48856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pearson-specter.iacarbonell.com"] [uri "/.env.save"] [unique_id "aquitTC-lNcPiSQK_eWEMwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack