Anonymous
2026-09-04 05:54:58
(1 hour ago)
Portscan: TCP/443, TCP/8080 (3x), TCP/8443 (3x)
Port Scan
🇺🇸
TPI-Abuse
2026-09-04 05:04:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:04:31.195495 2026] [security2:error] [pid 31267:tid 31267] [client 34.177.84.189:61776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oxfordgliding.com"] [uri "/@fs/.env.staging"] [unique_id "appRXyw5YgjkimpxwkiRpgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 04:49:42
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.177.84.189 (SG/Singapore/189.84.17 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.177.84.189 (SG/Singapore/189.84.177.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 04:11:32
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:11:25.282290 2026] [security2:error] [pid 26578:tid 26578] [client 34.177.84.189:59344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "supaskillsdata.gregorii.com"] [uri "/@fs/root/.env"] [unique_id "appE7XwUJASdIdqev_Fs3QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 04:01:00
(2 hours ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:01:10
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:01:03.417501 2026] [security2:error] [pid 10921:tid 10921] [client 34.177.84.189:9688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.deversonandtanack.com"] [uri "/@fs/app/.env"] [unique_id "apo0b6NSs9a1U8zJVPSk7gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 02:26:37
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 02:20:03
(4 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
Viveronese
2026-09-04 01:17:48
(5 hours ago)
HTTP vulnerability scanning
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:15:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.84.189 (189.84.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:15:34.693096 2026] [security2:error] [pid 31158:tid 31239] [client 34.177.84.189:15674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cargosanibel.newleafpro.com"] [uri "/@fs/app/.env"] [unique_id "apobtqhy8WggFRLPpGNpCgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 01:05:18
(5 hours ago)
Too many Status 40X (27)
Scanning/Probing (26)
Brute-Force
Web App Attack
Anonymous
2026-09-04 01:01:18
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇪🇸
librebit
2026-09-04 00:51:41
(6 hours ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇮🇹
CoreTech srl
2026-09-04 00:23:56
(6 hours ago)
cloudlinux2 fail2ban: 2026-09-04 02:18:56,639 fail2ban.filter [1472]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 02:18:56,639 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.75.241.106 - 2026-09-04 02:18:56cloudlinux2 fail2ban: 2026-09-04 02:19:38,744 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Unban 180.195.145.11cloudlinux2 fail2ban: 2026-09-04 02:19:53,690 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 136.65.5.245 - 2026-09-04 02:19:53cloudlinux2 fail2ban: 2026-09-04 02:20:03,263 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.26.250.138 - 2026-09-04 02:20:03cloudlinux2 fail2ban: 2026-09-04 02:20:15,546 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 193.19.109.132 - 2026-09-04 02:20:14cloudlinux2 fail2ban: 2026-09-04 02:21:35,098 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.177.84.189 - 2026-09-04 02:21:35cloudlinux2 fail2ban: 2026-09-04 02:21:35,107 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.177.84.189 - 2026-09-04 02:21:35cloudlinux2 fail2b
show less
Web App Attack
Anonymous
2026-09-03 23:17:12
(7 hours ago)
Bot / seems abusive / Apache connections: 55
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack