๐ฉ๐ช
Bedios GmbH
2026-08-31 03:26:17
(1 day ago)
Login credentials theft attempt
Hacking
๐ฌ๐ง
consul.to
2026-08-31 02:28:39
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 00:52:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 20:52:34.765349 2026] [security2:error] [pid 16782:tid 16782] [client 27.21.27.245:51908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.glassicannex.org"] [uri "/.env"] [unique_id "apN-0snsOgeePfzBtEQKFwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 23:58:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 19:58:32.197995 2026] [security2:error] [pid 11346:tid 11346] [client 27.21.27.245:56186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.boatpeople.org"] [uri "/.env"] [unique_id "apNyKEc6LaEJZBqVRdT7dgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 23:17:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 19:17:06.679274 2026] [security2:error] [pid 31601:tid 31611] [client 27.21.27.245:52296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bhhg.org"] [uri "/.env"] [unique_id "apNocjCn29IIW3wHWS65ywAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-08-29 22:56:29
(2 days ago)
27.21.27.245 - - [29/Aug/2026:23:56:37 +0100] "GET /users/sign_in HTTP/1.1" 404 6331 "-" "Mozilla/5. ...
show more
27.21.27.245 - - [29/Aug/2026:23:56:37 +0100] "GET /users/sign_in HTTP/1.1" 404 6331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
27.21.27.245 - - [29/Aug/2026:23:56:39 +0100] "GET /login/index.php HTTP/1.1" 404 6331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
27.21.27.245 - - [29/Aug/2026:23:56:39 +0100] "GET /geoserver/rest/about/version.json HTTP/1.1" 404 6331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-29 22:24:23
(2 days ago)
27.21.27.245 - - [29/Aug/2026:23:24:21 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows ...
show more
27.21.27.245 - - [29/Aug/2026:23:24:21 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
2026/08/29 23:24:21 [error] 380594#380594: *1434672 access forbidden by rule, client: 27.21.27.245, server: bestasquadradas.org, request: "GET /.env HTTP/2.0", host: "bestasquadradas.org", referrer: "https://www.bestasquadradas.org/.env"
27.21.27.245 - - [29/Aug/2026:23:24:21 +0100] "GET /.env HTTP/2.0" 403 1045 "https://www.bestasquadradas.org/.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 22:00:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 18:00:41.995835 2026] [security2:error] [pid 32268:tid 32268] [client 27.21.27.245:34532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bencramer.org"] [uri "/.env"] [unique_id "apNWif72gIcgsp3GpVja2AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 21:42:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 17:42:08.491137 2026] [security2:error] [pid 12504:tid 12563] [client 27.21.27.245:59232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.behaviorhealth.org"] [uri "/.env"] [unique_id "apNSMG74kL9e5VZYRz-QQAAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-29 21:29:49
(2 days ago)
27.21.27.245 - - [29/Aug/2026:17:29:49 -0400] "GET /.env HTTP/1.1" 403 6270 "https://www.becauseofje ...
show more
27.21.27.245 - - [29/Aug/2026:17:29:49 -0400] "GET /.env HTTP/1.1" 403 6270 "https://www.becauseofjenna.org/.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 21:22:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 17:22:09.391985 2026] [security2:error] [pid 17174:tid 17174] [client 27.21.27.245:40216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bearssd.org"] [uri "/.env"] [unique_id "apNNgSe6MLECKH4YLPLiRAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 12:30:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:30:46.984567 2026] [security2:error] [pid 21571:tid 21571] [client 27.21.27.245:52350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fedeoliva.cl"] [uri "/.env"] [unique_id "apLQ9hWMfhT2VYbCVmjxvgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 11:39:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 27.21.27.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:39:23.322875 2026] [security2:error] [pid 26178:tid 26178] [client 27.21.27.245:43768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dossat.cl"] [uri "/.env"] [unique_id "apLE67LHeaJ6nxXwz461sgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
vfAcceloReporter
2026-08-29 00:22:35
(3 days ago)
27.21.27.245 - - [28/Aug/2026:21:22:34 -0300] "GET /.env HTTP/1.1" 500 579 "-" "Mozilla/5.0 (Windows ...
show more
27.21.27.245 - - [28/Aug/2026:21:22:34 -0300] "GET /.env HTTP/1.1" 500 579 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Brute-Force
Web App Attack
Exploited Host
๐ง๐ท
Halux
2026-08-28 23:28:13
(3 days ago)
27.21.27.245 Probing protected path or service
Web App Attack