🇩🇪
s@ch@
2026-09-08 20:30:01
(18 hours ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:11:45
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:11:38.004499 2026] [security2:error] [pid 24369:tid 24369] [client 34.178.16.191:3096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.javierreinoso.com"] [uri "/@fs/src/.env"] [unique_id "aqBr-kSdq_mkdl4KEDkXXwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 20:00:03
(19 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:33:47
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:33:40.656646 2026] [security2:error] [pid 29896:tid 29896] [client 34.178.16.191:50616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "2pollards.com"] [uri "/@fs/app/.env"] [unique_id "aqBjFGXsJFwD1KBxyxHm-gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:59:31
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:59:22.990539 2026] [security2:error] [pid 31388:tid 31388] [client 34.178.16.191:28104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.monogay.org"] [uri "/@fs/.env"] [unique_id "aqBbCtCPSLUO743NwKR0xAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-08 18:53:51
(20 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇬🇧
consul.to
2026-09-08 18:51:42
(20 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-08 18:20:13
(20 hours ago)
Web Attack Vite Arbitrary File Read Vulnerability
Web App Attack
Anonymous
2026-09-08 18:15:48
(21 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.forms.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.forms.mastermind.gr; logs=/var/log/httpd/domains/tmg.gr.forms.log; samples=/@fs/src/.env?raw?? | /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? | /@fs/.env?raw??
show less
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-08 17:47:57
(21 hours ago)
168 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 17:10:14
(22 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:10:12
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.16.191 (191.16.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:10:06.161662 2026] [security2:error] [pid 16636:tid 16636] [client 34.178.16.191:32326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.infrared-heaters.us"] [uri "/@fs/.env"] [unique_id "aqBBbrxCUKPa-oGKZOzCqQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-08 17:04:21
(22 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇫🇮
YF
2026-09-08 17:00:26
(22 hours ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇩🇪
Viveronese
2026-09-08 16:44:25
(22 hours ago)
HTTP vulnerability scanning
Web App Attack