🇧🇪
cmbplf
2026-09-08 21:28:47
(1 day ago)
1.096 requests with url.path *.env
460 requests with url.path *credentials.json
437 requests with ...
show more
1.096 requests with url.path *.env
460 requests with url.path *credentials.json
437 requests with url.path *config.json
425 requests with url.path *.azure/*
show less
Brute-Force
Bad Web Bot
🇩🇪
pscriptos
2026-09-08 20:08:54
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
melroy89
2026-09-08 19:38:11
(1 day ago)
34.125.158.31 - - [08/Sep/2026:21:37:30 +0200] "GET / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (X11; Linux ...
show more
34.125.158.31 - - [08/Sep/2026:21:37:30 +0200] "GET / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36" "games.melroy.org" 0.001
34.125.158.31 - - [08/Sep/2026:21:37:35 +0200] "GET / HTTP/1.1" 403 524 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "games.melroy.org" 0.000
34.125.158.31 - - [08/Sep/2026:21:37:35 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 403 524 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "games.melroy.org" 0.000
34.125.158.31 - - [08/Sep/2026:21:37:35 +0200] "GET / HTTP/1.1" 403 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36" "games.melroy.org" 0.001
34.125.158.31 - - [08/Sep/2026:21:37:35 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:32:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:32:02.876125 2026] [security2:error] [pid 28782:tid 28782] [client 34.125.158.31:22884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lucid-hq.com"] [uri "/@fs/.env"] [unique_id "aqBUogygZok5qpqe_pZJPQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-08 18:10:39
(1 day ago)
34.125.158.31 - - [08/Sep/2026:14:10:39 -0400] "GET /@fs/.env?raw?? HTTP/1.1" 404 6018 "-" "Mozilla/ ...
show more
34.125.158.31 - - [08/Sep/2026:14:10:39 -0400] "GET /@fs/.env?raw?? HTTP/1.1" 404 6018 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; [email protected] )"
34.125.158.31 - - [08/Sep/2026:14:10:39 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 6018 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.125.158.31 - - [08/Sep/2026:14:10:39 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 6018 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:121.11) Gecko/20100101 Firefox/121.11; compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot"
...
show less
Web App Attack
🇳🇱
debestelapp
2026-09-08 17:45:12
(1 day ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:30:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:30:36.402926 2026] [security2:error] [pid 24599:tid 24599] [client 34.125.158.31:19210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.natursac.com"] [uri "/@fs/.env"] [unique_id "aqBGPNlY65yuGq8Cs2bBGAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:50:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:50:29.129106 2026] [security2:error] [pid 10177:tid 10177] [client 34.125.158.31:2236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mariarozella.com"] [uri "/@fs/src/.env"] [unique_id "aqA81XStiA8pj43JufDRdwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 16:35:02
(2 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:08:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:08:05.904352 2026] [security2:error] [pid 23824:tid 23824] [client 34.125.158.31:24396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tand.es"] [uri "/@fs/app/.env"] [unique_id "aqAy5ddsrVyzdwgW1JxM0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
DRI
2026-09-08 15:53:43
(2 days ago)
Web attack/Malicious activity detected
Web App Attack
🇫🇷
Octopuce
2026-09-08 15:37:02
(2 days ago)
Aggressive web search of vulnerable pages: /images../.env /.docker/.env /assets../.env /uploads../.e ...
show more
Aggressive web search of vulnerable pages: /images../.env /.docker/.env /assets../.env /uploads../.env /config/.env ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:16:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.158.31 (31.158.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:16:05.534802 2026] [security2:error] [pid 13799:tid 13799] [client 34.125.158.31:53230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mark.rawlings.name"] [uri "/@fs/.env"] [unique_id "aqAmtVrAiExu35hp8NOY-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 15:05:32
(2 days ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-08 14:35:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack