๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 21:59:43
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-07.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-07 10:37:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:37:04.690151 2026] [security2:error] [pid 7717:tid 7717] [client 34.27.193.195:11714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teamgravity.ca"] [uri "/@fs/app/.env"] [unique_id "ap6T0AnbYhDd_Q3iaB9dGgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-07 10:32:11
(1 week ago)
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=34.27.193.195 richieste=288 rischio=ALT ...
show more
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=34.27.193.195 richieste=288 rischio=ALTO score=17 motivi=molte_richieste,diverse_uri_uniche,molti_404,ua_script_bot,path_sospetti,poco_statico,dinamico cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-07 10:27:29
(1 week ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 10:04:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:03:55.367442 2026] [security2:error] [pid 17977:tid 17977] [client 34.27.193.195:46710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.garthp.com"] [uri "/@fs/.env.local"] [unique_id "ap6MC4j6T0lTArHlZ92MeAAAAG4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-07 10:01:28
(1 week ago)
Aggressive web search of vulnerable pages: /uploads../.env /_nuxt/../.env /assets../.env /v2/.env /. ...
show more
Aggressive web search of vulnerable pages: /uploads../.env /_nuxt/../.env /assets../.env /v2/.env /.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 09:34:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:34:04.455277 2026] [security2:error] [pid 15929:tid 15929] [client 34.27.193.195:58266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cicone.net"] [uri "/@fs/.env.production"] [unique_id "ap6FDGw_tOVgut0AtE8MgQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 08:50:13
(1 week ago)
Bot / seems abusive / Apache connections: 32
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-07 08:45:48
(1 week ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-07 08:28:43
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.27.193.195 (US/United States/195.193 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.27.193.195 (US/United States/195.193.27.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-07 08:11:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:11:50.152430 2026] [security2:error] [pid 1440:tid 1440] [client 34.27.193.195:28482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.avmarep.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap5xxsSL2F_wePJTSiUtwwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-07 07:33:47
(1 week ago)
3.086 requests with url.path */@fs/*
756 requests with url.path *.aws/*
309 requests with url.pat ...
show more
3.086 requests with url.path */@fs/*
756 requests with url.path *.aws/*
309 requests with url.path *.config/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-07 07:28:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:28:30.375769 2026] [security2:error] [pid 6675:tid 6675] [client 34.27.193.195:58550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.gilbertortegajewelry.com"] [uri "/@fs/.env.development"] [unique_id "ap5nno2_aabGhQR73M_9WQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-07 07:06:02
(1 week ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 06:35:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.193.195 (195.193.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:35:02.970540 2026] [security2:error] [pid 21273:tid 21273] [client 34.27.193.195:11110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.urie.to"] [uri "/@fs/root/.env"] [unique_id "ap5bFgVuZXLr6z0sZgVJdgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack