Anonymous
2026-09-15 18:16:48
(15 minutes ago)
34.27.83.69 - - [15/Sep/2026:20:16:36 +0200] "GET /.git/config HTTP/2.0" 403 272 "-" "Mozilla/5.0 (c ...
show more
34.27.83.69 - - [15/Sep/2026:20:16:36 +0200] "GET /.git/config HTTP/2.0" 403 272 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
🇩🇪
sdos.es
2026-09-15 18:00:13
(31 minutes ago)
"URL file extension is restricted by policy - .backup"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:43:08
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:42:59.776914 2026] [security2:error] [pid 14420:tid 14420] [client 34.27.83.69:49788] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digifonics.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digifonics.com"] [uri "/rclone.conf"] [unique_id "aql1k3U2EdOfuQH72uf_YAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-15 16:31:20
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.27.83.69 (US/United States/69.83.27.3 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 34.27.83.69 (US/United States/69.83.27.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.27.83.69 - - [15/Sep/2026:18:31:11 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 403 207 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "34.27.83.69" host=digiampaolo.it
show less
Port Scan
🇫🇷
Octopuce
2026-09-15 16:22:45
(2 hours ago)
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env ...
show more
Aggressive web search of vulnerable pages: /userfiles?path=../../.env /userfiles?path=../../../.env /userfiles?path=../../../../.env /userfiles ...
show less
Web App Attack
🇫🇷
regishoussin
2026-09-15 16:07:11
(2 hours ago)
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100180): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-15 16:07 UTC.
show less
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-15 15:56:06
(2 hours ago)
Try to access /.env?import&raw
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 15:54:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:54:29.847343 2026] [security2:error] [pid 27518:tid 27518] [client 34.27.83.69:42432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dietzengineers.com"] [uri "/.env"] [unique_id "aqlqNVpEtb3F1XHUN5nKFgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 15:35:01
(2 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-15 15:24:44
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-15 15:21:11
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:21:06.003038 2026] [security2:error] [pid 15849:tid 15849] [client 34.27.83.69:50960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||diepeveen.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "diepeveen.net"] [uri "/rclone.conf"] [unique_id "aqliYozNBWkrKJvJL8DpTgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-15 14:59:21
(3 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-15 14:58:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.83.69 (69.83.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:58:46.733261 2026] [security2:error] [pid 1694:tid 1694] [client 34.27.83.69:48508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diegogamazo.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqldJl7GhlF6QYf0BtasaQAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-15 14:54:13
(3 hours ago)
URL Probing: /pi.php
Web App Attack
🇩🇪
Bedios GmbH
2026-09-15 14:48:29
(3 hours ago)
Keyfile theft attempt
Hacking