๐บ๐ธ
TPI-Abuse
2026-09-04 15:17:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.178.32 (32.178.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.178.32 (32.178.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:17.985796 2026] [security2:error] [pid 20829:tid 20829] [client 34.48.178.32:43476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rokket.com"] [uri "/.env.save"] [unique_id "aprg_WFXeORQeicqnu87FgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-04 14:57:51
(1 week ago)
34.48.178.32 - - [04/Sep/2026:16:57:49 +0200] "GET /.env.example HTTP/1.1" 403 5027 "-" "crusader-wo ...
show more
34.48.178.32 - - [04/Sep/2026:16:57:49 +0200] "GET /.env.example HTTP/1.1" 403 5027 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Celtic
2026-09-04 14:10:07
(1 week ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-04 14:06:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.178.32 (32.178.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.178.32 (32.178.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:06:26.056137 2026] [security2:error] [pid 9342:tid 9342] [client 34.48.178.32:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.perl-photo.com"] [uri "/.env"] [unique_id "aprQYv44gXhCSucjbuRBggAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-09-04 14:06:14
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.48.178.32 (US/United States/32.178.4 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.48.178.32 (US/United States/32.178.48.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-04 13:50:03
(1 week ago)
suspicious request in access.log
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-04 13:49:26
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.48.178.32 (US/United States/32.178.4 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.48.178.32 (US/United States/32.178.48.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-04 13:34:05
(1 week ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.48.178.32 (US/United States/32.178.48.34. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.48.178.32 (US/United States/32.178.48.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.48.178.32 - - [04/Sep/2026:15:34:02 +0200] "GET /.env.production HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.48.178.32 - - [04/Sep/2026:15:34:02 +0200] "GET /.env.bak HTTP/1.1" 406 4830 "-" "crusader-worker/1.0"
34.48.178.32 - - [04/Sep/2026:15:34:02 +0200] "GET /.env.save HTTP/1.1" 406 4829 "-" "crusader-worker/1.0"
show less
Port Scan
๐ฉ๐ช
ddobko
2026-09-04 13:27:33
(1 week ago)
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-04 11:05:07
(1 week ago)
Login credentials theft attempt
Hacking
๐ช๐ธ
alferez
2026-09-04 10:42:25
(1 week ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 10:40:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.48.178.32 (32.178.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.178.32 (32.178.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:39:54.177346 2026] [security2:error] [pid 4163:tid 4163] [client 34.48.178.32:47962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alpha-hk.com"] [uri "/.env.prod"] [unique_id "apqf-jroN_2Y942p9ueDdwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-04 09:52:05
(1 week ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-04 09:22:03
(1 week ago)
[FriSep0411:21:56.7130292026][security2:error][pid23242:tid23445][client34.48.178.32:0]ModSecurity:A ...
show more
[FriSep0411:21:56.7130292026][security2:error][pid23242:tid23445][client34.48.178.32:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.aidconsultancy.ch\"][uri\"/.env.bak\"][unique_id\"apqNtJ4Z7SX7xm1BLZ66zgAAAQ4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-04 09:06:02
(1 week ago)
Scanning/Probing (20)
Brute-Force
Web App Attack