🇩🇪
raph
2026-09-08 05:55:41
(17 minutes ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:39:48
(33 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:39:41.603251 2026] [security2:error] [pid 3199:tid 3199] [client 34.14.27.177:16784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.serpentstudios.com"] [uri "/@fs/src/.env"] [unique_id "ap-fnY5HBS0k1S0awxN8agAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 04:48:30
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Site.eu
2026-09-08 04:41:13
(1 hour ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
BlueWire Hosting
2026-09-08 04:16:41
(1 hour ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:15:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:15:30.232772 2026] [security2:error] [pid 15677:tid 15677] [client 34.14.27.177:54532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pocosfarm.littlehorndesign.com"] [uri "/@fs/.env"] [unique_id "ap-L4kQUfOIgtN7o5EiffQAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:27:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:27:12.296289 2026] [security2:error] [pid 19865:tid 19879] [client 34.14.27.177:51734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jonneher.com"] [uri "/@fs/.env"] [unique_id "ap-AkOiA7oCXpgeGAueAdgAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:12:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:12:08.227542 2026] [security2:error] [pid 31447:tid 31447] [client 34.14.27.177:64198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chooseyourowntrail.com"] [uri "/@fs/src/.env"] [unique_id "ap99CBdzAZ1X2Mc7LiqaMAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 02:46:01
(3 hours ago)
CloudLinux/Plesk alert - host=cloudlinux5 dominio=fontanacontarini.it ip=34.14.27.177 richieste=195 ...
show more
CloudLinux/Plesk alert - host=cloudlinux5 dominio=fontanacontarini.it ip=34.14.27.177 richieste=195 rischio=ALTO score=19 motivi=molte_richieste,molte_uri_uniche,ua_script_bot,path_sospetti,api,possibile_enumerazione_id,poco_statico,dinamico cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
🇫🇷
masterguru
2026-09-08 02:27:58
(3 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇨🇭
zynex
2026-09-08 02:17:59
(3 hours ago)
URL Probing: /@fs/app/.env
Web App Attack
🇩🇪
netclix.gr
2026-09-08 02:09:40
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.14.27.177 (BE/Belgium/177.27.14.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.14.27.177 (BE/Belgium/177.27.14.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-08 02:02:32
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:02:27.347569 2026] [security2:error] [pid 30321:tid 30321] [client 34.14.27.177:52456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.panama-boat-registration.com"] [uri "/@fs/root/.env"] [unique_id "ap9ss1ipFMlTtSCy-0mq9AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:44:49
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.27.177 (177.27.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:44:43.167443 2026] [security2:error] [pid 24050:tid 24050] [client 34.14.27.177:49122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.the-schlosser.net"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap9oi4_dEv4sLf_QjWITdgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
artful
2026-09-08 01:42:00
(4 hours ago)
Excessive errors ~1.7k in recent hours
Web App Attack