🇨🇭
SOC [GOLINE SA]
2026-09-07 08:04:39
(1 hour ago)
FortiGate detected IPS attack from IPv4 address 34.106.242.127
Hacking
🇨🇭
SOC [GOLINE SA]
2026-09-06 07:04:49
(1 day ago)
FortiGate detected IPS attack from IPv4 address 34.106.242.127
Hacking
🇮🇩
sockominfo
2026-09-06 04:00:34
(1 day ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam
🇺🇸
TPI-Abuse
2026-09-06 03:50:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:50:22.506231 2026] [security2:error] [pid 19884:tid 19884] [client 34.106.242.127:60092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.lynetteharris.net"] [uri "/wp-config.php.swp"] [unique_id "apzi_hZUtRbdceJ8kpFi5AAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
sockominfo
2026-09-06 03:00:12
(1 day ago)
Active Response: IP 34.106.242.127 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Re ...
show more
Active Response: IP 34.106.242.127 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇩🇪
todix
2026-09-06 02:58:46
(1 day ago)
Web App Attack Exploid from 34.106.242.127
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:23.553300 2026] [security2:error] [pid 28890:tid 28907] [client 34.106.242.127:48870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.djkirby.com"] [uri "/.env.save"] [unique_id "apzWzy7L9JDvMLGVQ8LyiAAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:45:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:45:02.216593 2026] [security2:error] [pid 30321:tid 30321] [client 34.106.242.127:43046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "giftsprinted.com"] [uri "/.env.backup"] [unique_id "apzFnr4IgmMCpnreJa08HwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:09:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:52.777690 2026] [security2:error] [pid 9684:tid 9684] [client 34.106.242.127:55592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.saratogaequity.com"] [uri "/.env.prod"] [unique_id "apy9YKVa0DIejuaqXdbvmQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-06 00:39:34
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.106.242.127 (US/United States/127.242.106.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.106.242.127 (US/United States/127.242.106.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:32:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:32:15.915208 2026] [security2:error] [pid 13329:tid 13329] [client 34.106.242.127:43030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barecreationsaz.com"] [uri "/.env.example"] [unique_id "apy0jzYdl1nJcRc0a2-AjAAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 00:19:30
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-06 00:05:49
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:54:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.242.127 (127.242.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:54:10.362373 2026] [security2:error] [pid 17308:tid 17308] [client 34.106.242.127:58996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.stinsonbeachsurfandkayak.com"] [uri "/.env.dev"] [unique_id "apyropCBY3WMoZZLMSKx4wAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sigurg
2026-09-05 23:53:19
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking