🇳🇱
homeshowdomain.nl
2026-09-08 22:01:02
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-07.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-07 20:55:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:55:13.218699 2026] [security2:error] [pid 21252:tid 21252] [client 34.48.219.192:26640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.yeswedeliver.org"] [uri "/@fs/root/.env"] [unique_id "ap8ksTPKvM4ePSTjqtfo0AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:27:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:27:24.465287 2026] [security2:error] [pid 8284:tid 8284] [client 34.48.219.192:36458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.tupansetc.com"] [uri "/@fs/.env.development"] [unique_id "ap8eLMmr8fWtEu-MVRsDXQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 19:40:39
(1 day ago)
3.708 requests with url.path */@fs/*
860 requests with url.path *.aws/*
276 requests with url.pat ...
show more
3.708 requests with url.path */@fs/*
860 requests with url.path *.aws/*
276 requests with url.path *.config/*
219 requests with url.path *.ssh/*
106 requests with url.path *config.php
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 19:39:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:39:29.051035 2026] [security2:error] [pid 10515:tid 10515] [client 34.48.219.192:34834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.snowmanholidaycards.com"] [uri "/@fs/.env.local"] [unique_id "ap8S8Qll7AREwhBoH7BTKgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 19:33:19
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
pscriptos
2026-09-07 18:19:28
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 17:25:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:25:32.106545 2026] [security2:error] [pid 2157143:tid 2157143] [client 34.48.219.192:11374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nancyscafeandcatering.com"] [uri "/@fs/.env"] [unique_id "ap7zjCwqTsA8FeWT8EomzgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
WebNiraj
2026-09-07 17:22:00
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.48.219.192 (US/United States/192.219.48.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.48.219.192 (US/United States/192.219.48.34.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
🇳🇱
Site.eu
2026-09-07 17:03:38
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 16:37:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:36:52.169164 2026] [security2:error] [pid 18859:tid 18859] [client 34.48.219.192:9174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "belintxon.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap7oJFMjxvkQMB2m9piBvQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-07 16:17:22
(1 day ago)
Common web attack from 34.48.219.192.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:12:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.48.219.192 (192.219.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:12:41.863298 2026] [security2:error] [pid 5605:tid 5723] [client 34.48.219.192:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.raytbrown.com"] [uri "/@fs/.env"] [unique_id "ap7ieT2YA4KZBVkn7lNegAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 15:57:10
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-07 15:45:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack