🇫🇷
Baking333
2026-09-07 03:22:27
(3 hours ago)
[redacted] 34.27.19.62 - - [07/Sep/2026:04:22:25 +0100] "GET /.aws/config HTTP/1.1" 302 1574 0/57337 ...
show more
[redacted] 34.27.19.62 - - [07/Sep/2026:04:22:25 +0100] "GET /.aws/config HTTP/1.1" 302 1574 0/57337 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://[redacted]/)" [redacted] 34.27.19.62 - - [07/Sep/2026:04:22:25 +0100] "GET /.git/HEAD HTTP/1.1" 302 6793 0/59587 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 03:05:38
(3 hours ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
🇩🇪
YF
2026-09-07 03:00:14
(3 hours ago)
404 errors Vulnerability scan
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 02:19:10
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 00:39:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:39:09.226614 2026] [security2:error] [pid 1324:tid 1324] [client 34.27.19.62:33058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bwmurphy.com"] [uri "/.git/HEAD"] [unique_id "ap4Hrfk2Vibb_RCyNFTZwwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:50:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:49:58.569630 2026] [security2:error] [pid 11734:tid 11755] [client 34.27.19.62:58994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sh2.lol"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "ap38JqiqcDWugjfHnMJC7wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:25:09
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:25:01.620708 2026] [security2:error] [pid 2728:tid 2728] [client 34.27.19.62:36720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kristywernerauthor.com"] [uri "/img../.env"] [unique_id "ap32TXvf57H7pCm0gmfWuwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-06 22:57:20
(8 hours ago)
2026/09/06 23:57:17 [error] 380594#380594: *3336188 access forbidden by rule, client: 34.27.19.62, s ...
show more
2026/09/06 23:57:17 [error] 380594#380594: *3336188 access forbidden by rule, client: 34.27.19.62, server: apcoelho.pt, request: "GET /img../.env HTTP/2.0", host: "apcoelho.pt"
2026/09/06 23:57:17 [error] 380594#380594: *3336198 access forbidden by rule, client: 34.27.19.62, server: apcoelho.pt, request: "GET /uploads../.env HTTP/2.0", host: "apcoelho.pt"
2026/09/06 23:57:19 [error] 380594#380594: *3336211 access forbidden by rule, client: 34.27.19.62, server: apcoelho.pt, request: "GET /dashboard%2F.env HTTP/2.0", host: "apcoelho.pt"
show less
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 22:17:54
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-09-06 20:51:01
(10 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-06 20:35:23
(10 hours ago)
429 requests with url.path */@fs/*
154 requests with url.path *.oci/*
133 requests with url.path ...
show more
429 requests with url.path */@fs/*
154 requests with url.path *.oci/*
133 requests with url.path */proc/*
show less
Brute-Force
Bad Web Bot
🇬🇧
consul.to
2026-09-06 20:24:23
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
LRob
2026-09-06 20:18:57
(10 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/.env | 2026-09-06 20:18 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:37:38
(11 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:949110) triggered by 34.27.19.62 (62.19.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:37:31.156230 2026] [security2:error] [pid 17186:tid 17186] [client 34.27.19.62:47916] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "toxicnation.org"] [uri "/rclone.conf"] [unique_id "ap3A--7RFrKkkeHWXpsfdgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 19:14:38
(11 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack