๐บ๐ธ
TPI-Abuse
2026-09-03 20:25:52
(17 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:25:48.356360 2026] [security2:error] [pid 23238:tid 23253] [client 34.91.58.54:27688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bags.delapiazza.com"] [uri "/@fs/root/.env"] [unique_id "apnXzBYq35hniGWA4aEtngAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 19:50:51
(52 minutes ago)
Malicious activity detected
DDoS Attack
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-03 19:40:10
(1 hour ago)
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-03 19:35:01
(1 hour ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 19:28:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:28:18.013219 2026] [security2:error] [pid 7798:tid 7798] [client 34.91.58.54:49498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ifmamasang.com"] [uri "/@fs/app/.env"] [unique_id "apnKUslTfp6LCouKDpFhDAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 19:01:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:01:31.594478 2026] [security2:error] [pid 9884:tid 9884] [client 34.91.58.54:5236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tijuana-bibles.tijuanabible.org"] [uri "/@fs/root/.env"] [unique_id "apnECzG8ZqZx37hq_CuwagAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-03 19:00:07
(1 hour ago)
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=34.91.58.54 richieste=249 rischio=ALTO ...
show more
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=34.91.58.54 richieste=249 rischio=ALTO score=22 motivi=molte_richieste,molte_uri_uniche,molti_404,errori_5xx,ua_script_bot,path_sospetti,api,poco_statico,dinamico cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-03 18:33:32
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:33:29.131679 2026] [security2:error] [pid 1600440:tid 1600457] [client 34.91.58.54:12250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pwihatah.com"] [uri "/@fs/.env"] [unique_id "apm9eaCyJIsNKL9klsEvnQAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
MatStef132
2026-09-03 18:11:00
(2 hours ago)
MatShield L7: blocked on ptero.mathost.eu (secret-path-probe)
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 18:04:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:04:15.101779 2026] [security2:error] [pid 2239:tid 2239] [client 34.91.58.54:43158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.passy.us"] [uri "/@fs/../.env"] [unique_id "apm2n-fL3Ag39_J80x0EjgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-03 17:46:35
(2 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /.docker/.env /.env.local ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /uploads../.env /.docker/.env /.env.local /images../.env ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 17:08:36
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.58.54 (54.58.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:08:27.624564 2026] [security2:error] [pid 19888:tid 19894] [client 34.91.58.54:52484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.michaelmercier.com"] [uri "/@fs/app/.env"] [unique_id "apmpixMXZmnTzB846YOsrgAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 17:04:08
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-03 16:44:58
(3 hours ago)
Aggressive web scan
Web App Attack
๐ฎ๐น
VHosting
2026-09-03 16:40:03
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack