Anonymous
2026-08-28 13:30:03
(1 minute ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan
πΏπ¦
conure.sh
2026-08-28 12:14:58
(1 hour ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 8s
Web App Attack
π³π±
Site.eu
2026-08-28 12:05:55
(1 hour ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-28 09:45:12
(3 hours ago)
Bot / seems abusive / Apache connections: 70
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 09:17:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 05:17:30.861074 2026] [security2:error] [pid 26892:tid 26892] [client 34.125.169.3:62356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ashotofcoffee.com"] [uri "/@fs/app/.env"] [unique_id "apFSKjiVHjzXXdz4pXODnAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-08-28 09:11:14
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.169.3 (US/United States/3.169. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.125.169.3 (US/United States/3.169.125.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
π²πΎ
Rizzy
2026-08-28 08:39:23
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 08:16:54
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 04:16:46.502297 2026] [security2:error] [pid 25916:tid 25916] [client 34.125.169.3:60758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ps-omega.com"] [uri "/@fs/.env"] [unique_id "apFD7l_eBhJJhgyjvENM0QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 07:54:41
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:54:36.272446 2026] [security2:error] [pid 23154:tid 23154] [client 34.125.169.3:26576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rntoday.com"] [uri "/@fs/src/.env"] [unique_id "apE-vM5WNIpiuFcbHh9b2wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 07:39:18
(5 hours ago)
Aggressive Robot or Attack DDOS
DDoS Attack
π·πΊ
DZBOT
2026-08-28 07:08:25
(6 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π¬π§
Aetherweb Ark
2026-08-28 06:41:47
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.125.169.3 (US/United States/3.169.125.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.125.169.3 (US/United States/3.169.125.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 04:49:16
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.169.3 (3.169.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:49:07.566926 2026] [security2:error] [pid 27913:tid 27913] [client 34.125.169.3:26066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.turtlehill.org"] [uri "/@fs/src/.env"] [unique_id "apETQyL2Iww65zUZlnpjnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
alferez
2026-08-28 04:47:50
(8 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
π§π·
Halux
2026-08-28 04:39:43
(8 hours ago)
34.125.169.3 Probing protected path or service
Web App Attack