๐บ๐ธ
TPI-Abuse
2026-09-29 00:39:48
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:39:41.972427 2026] [security2:error] [pid 23845:tid 23845] [client 34.27.159.246:36678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tradersworldmarket.com"] [uri "/.git/config"] [unique_id "arsIzfphpB3mnvd5HHFLSgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 23:59:32
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 19:59:24.788595 2026] [security2:error] [pid 17175:tid 17175] [client 34.27.159.246:53310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tradenaples.com"] [uri "/.git/config"] [unique_id "arr_XFlZCkC6ujSjRRaX9QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 20:55:15
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:55:07.937374 2026] [security2:error] [pid 21913:tid 21923] [client 34.27.159.246:59180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lead-sleds.com"] [uri "/.git/config"] [unique_id "arrUK-szKLjk4cEYC31XxQAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 08:13:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:13:37.797503 2026] [security2:error] [pid 8686:tid 8686] [client 34.27.159.246:54622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dojaservices.com"] [uri "/.git/config"] [unique_id "arohsb10hysoQuQw6NwhowAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 05:30:02
(1 day ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack
๐ง๐ช
cmbplf
2026-09-28 04:25:42
(1 day ago)
3.537 requests with url.path *.env
676 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-28 04:18:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-26 21:59:59
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-25.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-26 20:34:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.159.246 (246.159.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:34:06.345717 2026] [security2:error] [pid 22968:tid 22968] [client 34.27.159.246:40564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.arzoma.com"] [uri "/.git/config"] [unique_id "argsPtTJAJqqOiFxLRSW0AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 05:14:18
(4 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ง๐ท
dominioz
2026-09-25 04:49:19
(4 days ago)
2026-09-25 04:48:59 GET /.env - - 34.27.159.246 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_1 ...
show more
2026-09-25 04:48:59 GET /.env - - 34.27.159.246 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 245
2026-09-25 04:48:59 GET /.env.local - - 34.27.159.246 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 245
2026-09-25 04:49:01 GET /.env.production - - 34.27.159.246 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 245
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:27:57
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 34.27.159.246 (246.159.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.27.159.246 (246.159.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:27:51.087487 2026] [security2:error] [pid 4947:tid 4947] [client 34.27.159.246:52400] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.creators.freedrm.org"] [uri "/.git/config"] [unique_id "arV5t_NOb9SaTrz0EDVdCAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 18:17:03
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
grassau.com
2026-09-24 17:55:39
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.27.159.246 (US/United States/Iowa/Co ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.27.159.246 (US/United States/Iowa/Council Bluffs/246.159.27.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
Bedios GmbH
2026-09-24 14:36:27
(4 days ago)
Login credentials theft attempt
Hacking