🇳🇱
homeshowdomain.nl
2026-09-09 22:02:47
(18 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-08.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-08 19:50:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:50:29.442425 2026] [security2:error] [pid 26163:tid 26163] [client 34.77.19.189:23642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.peakagronomysolutions.com"] [uri "/@fs/root/.env"] [unique_id "aqBnBUqiS-vhGC8x22M4fAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-08 19:07:06
(1 day ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Séfora Srl
2026-09-08 18:58:16
(1 day ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
🇧🇪
cmbplf
2026-09-08 18:38:48
(1 day ago)
533 requests with url.path *.azure/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 18:16:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:16:35.143070 2026] [security2:error] [pid 26584:tid 26584] [client 34.77.19.189:26310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.donaldcoleman.com"] [uri "/@fs/app/.env"] [unique_id "aqBRA_iqlzdLMbqiMzd9DgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:59:47
(1 day ago)
Aggressive web scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:40:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:39:59.743063 2026] [security2:error] [pid 23778:tid 23778] [client 34.77.19.189:35796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.flemingtonmartins.com"] [uri "/@fs/app/.env"] [unique_id "aqBIb63sFmDfqGtZy7wTAwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
cg-design.co.uk
2026-09-08 16:51:30
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.77.19.189 (BE/Belgium/189.19.77.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.77.19.189 (BE/Belgium/189.19.77.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
Site.eu
2026-09-08 16:31:45
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 16:29:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:29:39.005316 2026] [security2:error] [pid 32586:tid 32586] [client 34.77.19.189:7492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integritysecurity.us"] [uri "/@fs/app/.env"] [unique_id "aqA38zZZPEVgv1joHnefxAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 16:20:16
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 16:00:04
(2 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-08 15:55:31
(2 days ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:21:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.19.189 (189.19.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:21:17.287050 2026] [security2:error] [pid 15285:tid 15285] [client 34.77.19.189:20048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "etoyfun.vittariadesign.com"] [uri "/@fs/src/.env"] [unique_id "aqAn7UBYJd_q-TKxZOTcXQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack