π³π±
homeshowdomain.nl
2026-08-29 21:59:04
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
π¨π
π¨π Hosting
2026-08-29 05:10:08
(2 weeks ago)
Automated WAF report: 300-400 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 13:21:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:21:19.171734 2026] [security2:error] [pid 32506:tid 32506] [client 34.73.133.168:40736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bfpsamoa.com"] [uri "/@fs/root/.env"] [unique_id "apGLT7dSyKB3jG9qQXBQTAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
bensmithurst
2026-08-28 13:10:07
(3 weeks ago)
34.73.133.168 - - [28/Aug/2026:13:09:56 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
...
show more
34.73.133.168 - - [28/Aug/2026:13:09:56 +0000] "GET /@fs/../../.env?raw?? HTTP/1.1" 400 150 "-" "-"
34.73.133.168 - - [28/Aug/2026:13:10:06 +0000] "GET /@fs/../../../../../root/.env?raw?? HTTP/1.1" 400 150 "-" "-"
34.73.133.168 - - [28/Aug/2026:13:10:06 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ?raw?? HTTP/1.1" 400 150 "-" "-"
34.73.133.168 - - [28/Aug/2026:13:10:06 +0000] "GET /@fs/../../../../../app/.env?raw?? HTTP/1.1" 400 150 "-" "-"
34.73.133.168 - - [28/Aug/2026:13:10:06 +0000] "GET /@fs/../../../../../proc/self/environ?raw?? HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
π³π±
Brict IT
2026-08-28 11:57:10
(3 weeks ago)
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-08-28 11:17:34
(3 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΉπΌ
kk_it_man
2026-08-28 10:33:01
(3 weeks ago)
ET EXPLOIT VMware Spring Cloud Directory Traversal (CVE-2020-5410)
ET INFO ChatGPT-User Traffic De ...
show more
ET EXPLOIT VMware Spring Cloud Directory Traversal (CVE-2020-5410)
ET INFO ChatGPT-User Traffic Detected Inbound M1
ET INFO ChatGPT-User Traffic Detected Inbound M2
ET INFO Request to Hidden Environment File - Inbound
ET WEB_SERVER .bash_history Detected in URI
ET WEB_SERVER /etc/passwd Detected in URI
ET WEB_SERVER Likely Malicious Request for /proc/self/environ
ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208)
GPL WEB_SERVER .htpasswd access
GPL WEB_SERVER 403 Forbidden
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-08-28 10:21:19
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:21:13.409876 2026] [security2:error] [pid 19611:tid 19611] [client 34.73.133.168:56514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "odessatexas.us"] [uri "/@fs/.env"] [unique_id "apFhGSkcgxCdHB-OcJzoNwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
magnetosphere-tarpit
2026-08-28 09:28:30
(3 weeks ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 09:24:54
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:24:49.029966 2026] [security2:error] [pid 17046:tid 17046] [client 34.73.133.168:62394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noramsg.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apFT4YSC39hEaOlkrkiC8wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 08:26:41
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:26:35.539532 2026] [security2:error] [pid 10575:tid 10575] [client 34.73.133.168:55382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dougallbaillie.com"] [uri "/@fs/root/.env"] [unique_id "apFGO-0xpHyNjN5rxy1wTgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2026-08-28 08:18:42
(3 weeks ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
π¨π
backslash
2026-08-28 07:42:02
(3 weeks ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
π¬π§
consul.to
2026-08-28 07:21:34
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 07:15:44
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.133.168 (168.133.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:15:38.082960 2026] [security2:error] [pid 15910:tid 15910] [client 34.73.133.168:20886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.diuana.com"] [uri "/@fs/root/.env"] [unique_id "apE1mlGxEpNJyD-HbGTMaQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack