This IP address has been reported a total of
16
times from
15 distinct
sources.
125.165.33.11 was first reported on
, and the most recent report was
.
Recent Reports:
We have received reports of abusive activity from this IP address within the last week. It is
potentially still actively engaged in abusive activities.
181 requests with url.path *.aws/*
176 requests with url.path *phpinfo.php
151 requests with url. ...
show more181 requests with url.path *.aws/*
176 requests with url.path *phpinfo.php
151 requests with url.path /phpinfo.php
show less
(bot_kill_mega) Aggressive Bot Blocked: python 125.165.33.11 (ID/Indonesia/-): 1 in the last 4600 se ...
show more(bot_kill_mega) Aggressive Bot Blocked: python 125.165.33.11 (ID/Indonesia/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 125.165.33.11 - - [24/Aug/2026:06:41:36 +0300] "GET /var/cache/misc/assets/js/tygh/scripts-965b55cacaacc0715b613d976c94f4451763051236.js HTTP/1.1" 200 606611 "-" "python-httpx/0.28.1"
show less
[24/Aug/2026:05:49:08 +0300] -- 125.165.33.11 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET / ...
show more[24/Aug/2026:05:49:08 +0300] -- 125.165.33.11 Ban reason: Scanner [SENSITIVE_FILES] | Request: GET /.env/.env.bak HTTP/1.1
show less
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show moreProbing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env/.env.bak | 2026-08-24 02:10 UTC
show less
[MonAug2404:03:37.5870322026][security2:error][pid407514:tid407646][client125.165.33.11:0]ModSecurit ...
show more[MonAug2404:03:37.5870322026][security2:error][pid407514:tid407646][client125.165.33.11:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpanel.special-home.ch\"][uri\"/.env/.env.bak\"][unique_id\"aoumec_6-qnywIXSnJGcGAAAARU\"]
show less
Port Scan
Brute-Force
Web App Attack
Showing 1 to
15
of 16 reports
Think this IP has been falsely reported? You may request to have the associated
reports reviewed and removed.
Request Takedown ๐ฉ