๐ช๐ธ
alferez
2026-08-27 23:47:39
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:23:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:23:14.695388 2026] [security2:error] [pid 6098:tid 6098] [client 34.178.210.167:27030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mosherpit.com"] [uri "/@fs/root/.env"] [unique_id "apDG4iIegbxHiPmygchTAQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:57:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:57:09.785350 2026] [security2:error] [pid 29545:tid 29545] [client 34.178.210.167:24750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.juhoanttila.com"] [uri "/@fs/.env"] [unique_id "apDAxcCFu15W00fmeja92wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-08-27 22:35:51
(1 day ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:31:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:31:27.062122 2026] [security2:error] [pid 10627:tid 10627] [client 34.178.210.167:47910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drxcontent.com"] [uri "/@fs/root/.env"] [unique_id "apC6v_4nQHG5SrNguJT9iAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 22:25:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-27 22:11:05
(1 day ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐ฉ๐ช
XICTRON
2026-08-27 22:05:04
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:51:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:51:05.877568 2026] [security2:error] [pid 1182:tid 1182] [client 34.178.210.167:9048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kahnengineering.com"] [uri "/@fs/.env"] [unique_id "apCxSeL-T0KzcffB0ObhVQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:34:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:34:12.605819 2026] [security2:error] [pid 29500:tid 29500] [client 34.178.210.167:32646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.whmlradio.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apCtVPlNNU_u5HonZQT_1QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-27 21:17:27
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-08-27 21:15:12
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.178.210.167 (167.210.178.34.bc.googl ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.178.210.167 (167.210.178.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
updown.io
2026-08-27 21:08:02
(1 day ago)
{"level":"info","ts":1787864850.1422455,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1787864850.1422455,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.178.210.167","remote_port":"15888","client_ip":"34.178.210.167","proto":"HTTP/1.1","method":"GET","host":"82m8.status.updown.io","uri":"/","headers":{"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (iPhone; CPU iPhone OS 15_7_3 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) CriOS/107.0.5304.79 Mobile/15E148 Safari/537.36"],"Accept":["*/*"]}},"bytes_read":0,"user_id":"","duration":0.000063271,"size":0,"status":308,"resp_headers":{"Server":["Caddy"],"Connection":["close"],"Location":["https://82m8.status.updown.io/"],"Content-Type":[]}}
{"level":"info","ts":1787864855.0748684,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"34.178.210.167","remote_port":"2398","client_ip":"34.178.210.167","proto":"HTTP/1.1","method":"GET","host":"82m8.status.updown.io","uri":"/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??",
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:52:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.210.167 (167.210.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:52:46.343418 2026] [security2:error] [pid 21701:tid 21701] [client 34.178.210.167:22668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stevedemers.com"] [uri "/@fs/src/.env"] [unique_id "apCjnv7tjzk_yJWt72ojMQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-27 20:45:51
(1 day ago)
Excessive 404/403 errors
Brute-Force