🇩🇪
akasolutions.de
2026-09-08 05:16:07
(10 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.125.161.99 (US/United States/99.161. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.125.161.99 (US/United States/99.161.125.34.bc.googleusercontent.com)
show less
SQL Injection
🇲🇾
Rizzy
2026-09-08 05:15:28
(10 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 05:14:06
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 01:13:56.891512 2026] [security2:error] [pid 14321:tid 14335] [client 34.125.161.99:11246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dpiazza.com"] [uri "/@fs/src/.env"] [unique_id "ap-ZlHUmsa4YN6gj7NyeuQAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-08 04:56:56
(29 minutes ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:54:50
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:54:42.865664 2026] [security2:error] [pid 22931:tid 22931] [client 34.125.161.99:20578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nwuoregon.org"] [uri "/@fs/app/.env"] [unique_id "ap-VElQ8cjS103Y4zvQV9QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-08 04:50:41
(35 minutes ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:35:44
(50 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:35:40.411306 2026] [security2:error] [pid 3354:tid 3354] [client 34.125.161.99:23026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theknowledgemaster.com"] [uri "/@fs/src/.env"] [unique_id "ap-QnBRiEnTqfEMz956ROwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 03:57:36
(1 hour ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.161.99 (US/United States/99.16 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.161.99 (US/United States/99.161.125.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇫🇷
Felisse
2026-09-08 03:29:44
(1 hour ago)
CrowdSec ban: crowdsecurity/http-path-traversal-probing (duration: 3h59m57s)
Web App Attack
🇩🇪
LRob
2026-09-08 03:27:55
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/..%252f..%252f..%252f..%252f..%252froot/.env (+5 more) | 2026-09-08 03:27 UTC
show less
Hacking
Web App Attack
🇷🇺
DZBOT
2026-09-08 03:22:38
(2 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-08 03:19:12
(2 hours ago)
Bot / seems abusive / Apache connections: 53
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-08 03:06:52
(2 hours ago)
2026/09/08 03:06:51 [error] 3640628#3640628: *569041838 access forbidden by rule, client: 34.125.161 ...
show more
2026/09/08 03:06:51 [error] 3640628#3640628: *569041838 access forbidden by rule, client: 34.125.161.99, server: binixo.com.ua, request: "GET /@fs/.env?raw?? HTTP/1.1", host: "binixo.com.ua"
2026/09/08 03:06:51 [error] 3640628#3640628: *569041840 access forbidden by rule, client: 34.125.161.99, server: binixo.com.ua, request: "GET /@fs/app/.env?raw?? HTTP/1.1", host: "binixo.com.ua"
2026/09/08 03:06:51 [error] 3640628#3640628: *569041839 access forbidden by rule, client: 34.125.161.99, server: binixo.com.ua, request: "GET /@fs/root/.env?raw?? HTTP/1.1", host: "binixo.com.ua"
...
show less
Web App Attack
🇩🇪
todix
2026-09-08 02:15:54
(3 hours ago)
Web App Attack Exploid from 34.125.161.99
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:15:33
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.161.99 (99.161.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:15:27.449597 2026] [security2:error] [pid 13704:tid 13704] [client 34.125.161.99:57982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.crestrong.com"] [uri "/@fs/root/.env"] [unique_id "ap9vvx2rIFUHKZOCrdkX0QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack