🇳🇱
e.fierstra
2026-09-08 11:17:56
(3 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 10:49:20
(32 minutes ago)
34.125.15.158 - - [08/Sep/2026:18:49:19 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 403 162 "-" "Mozill ...
show more
34.125.15.158 - - [08/Sep/2026:18:49:19 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 403 162 "-" "Mozilla/5.0 (compatible; WhatsApp/10.0.2.1)"
show less
Brute-Force
SSH
Anonymous
2026-09-08 10:27:25
(54 minutes ago)
34.125.15.158 - - [08/Sep/2026:12:27:24 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 153 "-" "Mozilla/5 ...
show more
34.125.15.158 - - [08/Sep/2026:12:27:24 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.3; +https:///searchbot)"
show less
Web App Attack
🇩🇪
FD-IX
2026-09-08 10:06:38
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:18:40
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:18:36.452092 2026] [security2:error] [pid 4288:tid 4323] [client 34.125.15.158:10280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.davidholls.com"] [uri "/@fs/root/.env"] [unique_id "ap_E3Jz1W0EP-vC0Ow2kTwAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-08 07:39:33
(3 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signatur ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after matched multi-pattern attack signature. Evidence: AttackPattern: /@fs/ (Match: /@fs/)
show less
Hacking
Web App Attack
🇩🇪
ghostwarriors
2026-09-08 06:50:03
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇨🇦
john doe
2026-09-08 06:49:09
(4 hours ago)
SentinelBot: Secret-path hunting (5 distinct paths): Env File Hunting, Backup File Hunt (score: 73)
Bad Web Bot
🇫🇷
masterguru
2026-09-08 06:39:52
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.15.158 (US/United States/158.1 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.15.158 (US/United States/158.15.125.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-08 06:23:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:23:20.862193 2026] [security2:error] [pid 3037816:tid 3037816] [client 34.125.15.158:28190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tech.tonylai.com"] [uri "/@fs/src/.env"] [unique_id "ap-p2KMN3uFRJ79qOHvUVwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-08 06:21:41
(4 hours ago)
34.125.15.158 - - [08/Sep/2026:08:21:36 +0200] "GET /@fs/app/.aws/credentials?raw?? HTTP/1.1" 404 38 ...
show more
34.125.15.158 - - [08/Sep/2026:08:21:36 +0200] "GET /@fs/app/.aws/credentials?raw?? HTTP/1.1" 404 38320 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.4; +https://openai.com/gptbot) Chrome/133.0.7910.180 Safari/537.36 Edg/133.0.7910.180"
34.125.15.158 - - [08/Sep/2026:08:21:36 +0200] "GET /@fs/root/.aws/config?raw?? HTTP/1.1" 404 38320 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Google-Extended/1.0; +http://www.google.com/bot.html) Chrome/118.0.1674.52 Safari/537.36"
34.125.15.158 - - [08/Sep/2026:08:21:36 +0200] "GET /@fs/root/.aws/credentials.bak?raw?? HTTP/1.1" 404 38320 "-" "Mozilla/5.0 (compatible; TelegramBot/1.0)"
34.125.15.158 - - [08/Sep/2026:08:21:36 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 38314 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.2; +https://openai.com/gptbot) Chrome/130.0.8445.129
show less
Web App Attack
Hacking
Anonymous
2026-09-08 05:33:12
(5 hours ago)
Bot / seems abusive / Apache connections: 44
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:44:54
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:44:49.625771 2026] [security2:error] [pid 31856:tid 31856] [client 34.125.15.158:7050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.austintrauma.com"] [uri "/@fs/app/.env"] [unique_id "ap-Swa-WwpA3BE6T9xDCoAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 04:31:15
(6 hours ago)
964 requests with url.path *.aws/*
806 requests with url.path *credentials.json
780 requests with ...
show more
964 requests with url.path *.aws/*
806 requests with url.path *credentials.json
780 requests with url.path *config.json
109 requests with url.path *config.php
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 03:51:22
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.15.158 (158.15.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:51:16.811947 2026] [security2:error] [pid 14402:tid 14402] [client 34.125.15.158:58782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.boardingatthewedge.com"] [uri "/@fs/root/.env"] [unique_id "ap-GNMbAnuy1YDxE5cBmcwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack