๐ธ๐ฌ
fazar
2026-08-01 15:20:24
(13 minutes ago)
bad-behavior: 15 attempts from 34.12.136.201 on node: sgp03
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 15:19:44
(14 minutes ago)
CrowdSec: crowdsecurity/http-bad-user-agent | req: /api/.env | UA: Mozilla/5.0 (compatible; CensysIn ...
show more
CrowdSec: crowdsecurity/http-bad-user-agent | req: /api/.env | UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-01 14:29:32
(1 hour ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /wp-config.php.bak | 5 distinct paths | UA: TLM- ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /wp-config.php.bak | 5 distinct paths | UA: TLM-Audit-Scanner/1.0
show less
Hacking
๐ฎ๐ฉ
Burayot
2026-08-01 14:16:10
(1 hour ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.12.136.201 (201.136.12.34.bc.goog ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 34.12.136.201 (201.136.12.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-01 13:41:43
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐บ๐ธ
kosada.com
2026-08-01 12:17:33
(3 hours ago)
Web vulnerability probing: /api/config.json
Web App Attack
๐ฟ๐ฆ
conure
2026-08-01 12:03:03
(3 hours ago)
csagent: score 21.5: php 404 x1, wp-config backup grab x1, secrets grab x1; 2 domain(s) in 9s
Web App Attack
Anonymous
2026-08-01 11:49:53
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-08-01 11:29:02
(4 hours ago)
[01/Aug/2026:13:29:02.319605 +0200] am3Yfgb906CtNaTzKT1oMAAAAAM 34.12.136.201 41942 127.0.0.1 7081
[ ...
show more
[01/Aug/2026:13:29:02.319605 +0200] am3Yfgb906CtNaTzKT1oMAAAAAM 34.12.136.201 41942 127.0.0.1 7081
[01/Aug/2026:13:29:02.330008 +0200] am3Yflrma0UdH5jT8hRb8AAAAAI 34.12.136.201 41960 127.0.0.1 7081
[01/Aug/2026:13:29:02.332221 +0200] am3YfjYBkdsvbDjfB4qpWQAAAAc 34.12.136.201 41964 127.0.0.1 7081
...
show less
Web App Attack
๐ฉ๐ช
maxpower
2026-08-01 11:17:02
(4 hours ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.12.136.201 (201.136.12.34.bc.googleusercont ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.12.136.201 (201.136.12.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/01 13:16:58 [error] 2844492#2844492: *1087957 access forbidden by rule, client: 34.12.136.201, server: mediaqualitylab.com, request: "GET /wp-config.php.bak HTTP/1.1", host: "mail.mediaqualitylab.com"
2026/08/01 13:16:58 [error] 2844503#2844503: *1087961 access forbidden by rule, client: 34.12.136.201, server: mediaqualitylab.com, request: "GET /wp-config.php HTTP/1.1", host: "mail.mediaqualitylab.com"
2026/08/01 13:16:58 [error] 2844498#2844498: *1088057 access forbidden by rule, client: 34.12.136.201, server: mediaqualitylab.com, request: "GET /wp-config.php.old HTTP/1.1", host: "mail.mediaqualitylab.com"
show less
Port Scan
๐ฉ๐ช
DEV-DNS
2026-08-01 10:00:13
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐จ๐ญ
4server
2026-08-01 08:56:15
(6 hours ago)
[SatAug0110:56:09.3337222026][security2:error][pid2805004:tid2805319][client34.12.136.201:0]ModSecur ...
show more
[SatAug0110:56:09.3337222026][security2:error][pid2805004:tid2805319][client34.12.136.201:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webmail.aidconsultancy.ch\"][uri\"/.env.staging\"][unique_id\"am20qTLkIdu71e1zfvWZpwAAARY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
alecj.com
2026-08-01 07:28:55
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ฉ๐ช
akasolutions.de
2026-08-01 07:04:14
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.12.136.201 (201.136.12.34.bc.googleu ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.12.136.201 (201.136.12.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-08-01 07:00:31
(8 hours ago)
34.12.136.201 - - [01/Aug/2026:09:00:30 +0200] "GET /env.js HTTP/1.1" 404 834 "-" "Mozilla/5.0 Apple ...
show more
34.12.136.201 - - [01/Aug/2026:09:00:30 +0200] "GET /env.js HTTP/1.1" 404 834 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.12.136.201 - - [01/Aug/2026:09:00:30 +0200] "GET /env.json HTTP/1.1" 404 834 "-" "facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)"
34.12.136.201 - - [01/Aug/2026:09:00:30 +0200] "GET /.env HTTP/1.1" 403 837 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.12.136.201 - - [01/Aug/2026:09:00:30 +0200] "GET /.env.local HTTP/1.1" 403 837 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ClaudeBot/1.0; +mailto:[email protected] "
34.12.136.201 - - [01/Aug/2026:09:00:30 +0200] "GET /google-services.json HTTP/1.1" 404 834 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.12.136.201 - - [01/Aug/2026:09:00:30 +0200] "G
...
show less
DDoS Attack