πΊπΈ
julianalee.com
2026-09-22 17:58:00
(2 days ago)
21/Sep/26 10:05:21 #4793175 CRITICAL 3 34.75.28.27 GET /__vite_rsc_findSourceMapURL?file ...
show more
21/Sep/26 10:05:21 #4793175 CRITICAL 3 34.75.28.27 GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc - Local file inclusion - [GET:filename = file:///proc/self/environ] - union-city-ca-homes.com
21/Sep/26 10:05:21 #8408951 CRITICAL 520 34.75.28.27 GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///app/.env] - union-city-ca-homes.com
21/Sep/26 10:05:21 #1335670 CRITICAL 520 34.75.28.27 GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc - Data URI scheme or PHP wrappers - [GET:filename = file:///root/.aws/credentials] - union-city-ca-
show less
Hacking
π·πΈ
pexodelic
2026-09-22 03:35:02
(2 days ago)
Automated report from web, SSH and FTP server logs: 300 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 300 requests probing for exposed secrets (.env, .git, config files); 405 distinct non-existent paths requested (wordlist scanning); 898 HTTP 4xx responses. First reported 2026-09-21 16:05 UTC, last reported 2026-09-22 05:35 UTC; counts cover the current log rotation window.
show less
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 01:41:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:41:47.579927 2026] [security2:error] [pid 22778:tid 22778] [client 34.75.28.27:35756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.acmax.com"] [uri "/frontend/.env"] [unique_id "arHc2z9G_5JT5W4FQiz1ZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
masterguru
2026-09-22 01:28:59
(3 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:user-agent. (1100000-169)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-21 22:42:12
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:42:05.273656 2026] [security2:error] [pid 30632:tid 30723] [client 34.75.28.27:36520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vanillaguerrillapublishing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vanillaguerrillapublishing.com"] [uri "/z9x8c7v6b5-debug-trigger-vanillaguerrillapublishing.com"] [unique_id "arGyvTW9OP9Db4Q3BTbMNAAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 21:37:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:37:00.475292 2026] [security2:error] [pid 11424:tid 11424] [client 34.75.28.27:42206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vicsflooring.com"] [uri "/.env.js"] [unique_id "arGjfH3kQrYshQEbaC7AUwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 20:45:10
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:45:06.608643 2026] [security2:error] [pid 11111:tid 11111] [client 34.75.28.27:37246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.treeofloveproductions.com|F|2"] [data ".treeofloveproductions.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.treeofloveproductions.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.treeofloveproductions.com"] [unique_id "arGXUnVRKTOQMf_oKo5xSAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 20:14:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:13:55.377287 2026] [security2:error] [pid 25229:tid 25229] [client 34.75.28.27:33118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.abecasis.com"] [uri "/@fs/app/.env"] [unique_id "arGQA2ZMDaqdrEBFpPuVCgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 19:54:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:54:17.178570 2026] [security2:error] [pid 6171:tid 6171] [client 34.75.28.27:40278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.trhs70.com"] [uri "/ai/.env"] [unique_id "arGLaYjXkAcfVYFMPaRHWgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 19:30:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:30:32.161853 2026] [security2:error] [pid 21262:tid 21262] [client 34.75.28.27:48158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waynejarvi.com"] [uri "/.env.example"] [unique_id "arGF2GSP_lJPFrg8R1ZH0wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 18:28:40
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:28:36.570233 2026] [security2:error] [pid 12679:tid 12679] [client 34.75.28.27:37120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ucommsi.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ucommsi.com"] [uri "/z9x8c7v6b5-debug-trigger-ucommsi.com"] [unique_id "arF3VGjlBzhLaBmm9MdIkgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 18:13:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:13:09.151011 2026] [security2:error] [pid 10794:tid 10794] [client 34.75.28.27:60314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.anythingsoldworldwide.com"] [uri "/.env.production"] [unique_id "arFztUOki72KYHChhgffEQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 17:56:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:56:33.565007 2026] [security2:error] [pid 6512:tid 6512] [client 34.75.28.27:50272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tpdtuberental.com"] [uri "/admin/.env"] [unique_id "arFv0U9E-a8Sd017z8VByAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 17:41:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.28.27 (27.28.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:40:56.671038 2026] [security2:error] [pid 7661:tid 7661] [client 34.75.28.27:35088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegamblefamily.com"] [uri "/.next/.env"] [unique_id "arFsKAyrRubiy25a4NNLhAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
VanKoh
2026-09-21 17:06:13
(3 days ago)
(cpanel) Failed cPanel login from 34.75.28.27 (US/United States/South Carolina/North Charleston/27.2 ...
show more
(cpanel) Failed cPanel login from 34.75.28.27 (US/United States/South Carolina/North Charleston/27.28.75.34.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 34.75.28.27; Ports: *; Direction: 1; Trigger: LF_TRIGGER; Logs: [2026-09-21 11:06:10 -0600] info [cpaneld] 34.75.28.27 - - "GET /ssl/localhost.key HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-21 11:06:10 -0600] info [cpaneld] 34.75.28.27 - - "GET /.profile HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-21 11:06:10 -0600] info [cpaneld] 34.75.28.27 - - "GET /.zshrc HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-21 11:06:10 -0600] info [cpaneld] 34.75.28.27 - - "GET /@fs/app/.env?raw?? HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username [2026-09-21 11:06:10 -0600] info [cpaneld] 34.75.28.27 - - "POST /api/graphql HTTP/1.1" FAILED LOGIN cpaneld: login attempt without username
show less
Brute-Force