๐ฎ๐ณ
walkintoadmin
2026-09-16 14:02:55
(1 day ago)
GCP fleet: Vite /@fs/ path-traversal + cloud-credential harvester, spoofed bot UA; 293 reqs/1d, scan ...
show more
GCP fleet: Vite /@fs/ path-traversal + cloud-credential harvester, spoofed bot UA; 293 reqs/1d, scanner-path ratio 0.76, 0 real-user 200s
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-08 20:17:01
(1 week ago)
[TueSep0822:16:56.6153852026][security2:error][pid3061411:tid3061427][client34.80.33.29:0]ModSecurit ...
show more
[TueSep0822:16:56.6153852026][security2:error][pid3061411:tid3061427][client34.80.33.29:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"illibrodeilibri.ch\"][uri\"/@fs/.env\"][unique_id\"aqBtOB4jMecC_qX_twRurQAAAUE\"]
show less
Hacking
Web App Attack
๐ฎ๐น
Giando
2026-09-08 19:58:00
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-08 19:55:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:55:03.838606 2026] [security2:error] [pid 4959:tid 4959] [client 34.80.33.29:17292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.trancelucid.com"] [uri "/@fs/root/.env"] [unique_id "aqBoF3WuZNCtuWayPFT3ZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 19:50:59
(1 week ago)
XSS Attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-08 19:21:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:21:24.754503 2026] [security2:error] [pid 14739:tid 14739] [client 34.80.33.29:50138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.yubagals.com"] [uri "/@fs/src/.env"] [unique_id "aqBgNFJj2G-nQeBz6iXvYAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 19:00:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:00:15.774552 2026] [security2:error] [pid 5440:tid 5440] [client 34.80.33.29:26866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rosecityexpress.com"] [uri "/@fs/.env"] [unique_id "aqBbP5AoQNc9ygUWJVGL1QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-08 18:59:24
(1 week ago)
Login credentials theft attempt
Hacking
๐ง๐ช
cmbplf
2026-09-08 18:43:02
(1 week ago)
104 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-08 18:17:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:17:29.960095 2026] [security2:error] [pid 3100:tid 3125] [client 34.80.33.29:61918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.boatservicesgroup.com"] [uri "/@fs/root/.env"] [unique_id "aqBROfsZ34QsbkhdaXv97AAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 18:00:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:00:23.681389 2026] [security2:error] [pid 1884:tid 1884] [client 34.80.33.29:43394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fewo-eva.at"] [uri "/@fs/.env"] [unique_id "aqBNN9XOTFmhNu8XkLc27AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-08 17:37:51
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-08 17:29:04
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-08 17:19:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:19:48.054718 2026] [security2:error] [pid 12587:tid 12587] [client 34.80.33.29:29026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hacertests.com"] [uri "/@fs/src/.env"] [unique_id "aqBDtAIVVid0vykx-Id5NAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 16:56:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.33.29 (29.33.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:56:17.790175 2026] [security2:error] [pid 1248:tid 1328] [client 34.80.33.29:19538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.propertyinspectorsinc.com"] [uri "/@fs/src/.env"] [unique_id "aqA-MfVXKXnwOLXFzoLN8wAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack