🇨🇭
SOC [GOLINE SA]
2026-09-06 06:02:55
(3 hours ago)
FortiGate detected IPS attack from IPv4 address 34.121.3.64
Hacking
🇩🇪
LRob
2026-09-06 03:40:08
(5 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+3 more) | 2026-09-06 03:40 UTC
show less
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-06 03:34:06
(5 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.121.3.64 (US/United States/64.3.12 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.121.3.64 (US/United States/64.3.121.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
Anonymous
2026-09-06 03:29:44
(5 hours ago)
Bloqueado automaticamente por CrowdSec escenario crowdsecurity/http-sensitive-files
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 03:01:02
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:00:57.901475 2026] [security2:error] [pid 21358:tid 21358] [client 34.121.3.64:50496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ictsl.net"] [uri "/.env.backup"] [unique_id "apzXaRJjd0DaRsloEB59jwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ddobko
2026-09-06 02:27:31
(6 hours ago)
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 02:25:22
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:38:43
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:30:16
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:30:08.789668 2026] [security2:error] [pid 18697:tid 18697] [client 34.121.3.64:42204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "muranelli.com"] [uri "/wp-config.php.swp"] [unique_id "apzCIBtVsEjO8Y0qUe6XdQAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:47:36
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:47:30.986668 2026] [security2:error] [pid 3201:tid 3201] [client 34.121.3.64:43724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.guthrieclan.us"] [uri "/.env"] [unique_id "apy4ImuiRj_7NDhpHx7itQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:24:05
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:23:59.596505 2026] [security2:error] [pid 2098:tid 2098] [client 34.121.3.64:45724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limolaketahoe.com"] [uri "/.env"] [unique_id "apyyn4KNpey85kFMLpe6igAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:59:02
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:58:56.089122 2026] [security2:error] [pid 6042:tid 6042] [client 34.121.3.64:42960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeanboomergrenier.com"] [uri "/.env.backup"] [unique_id "apyswFJ8jaZ1o4lz_blfOwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Bedios GmbH
2026-09-05 23:25:34
(9 hours ago)
SQL backup theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:13:49
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.3.64 (64.3.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:13:44.214421 2026] [security2:error] [pid 26516:tid 26516] [client 34.121.3.64:44012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sykesclan.com"] [uri "/.env.save"] [unique_id "apyiKF4F3XPnv6cH21iiugAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-05 22:57:32
(10 hours ago)
Multiple WAF Violations
Web App Attack