🇺🇸
TPI-Abuse
2026-09-07 20:10:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:10:09.352904 2026] [security2:error] [pid 2120:tid 2120] [client 34.125.191.177:32130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.andrewweigel.name"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap8aIUCfpkRaIoAHBt0iPQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-07 20:01:23
(1 hour ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ❌ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:48:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:48:11.607864 2026] [security2:error] [pid 441:tid 441] [client 34.125.191.177:51776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saimedo.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap8U-7mVe6QzM0Ug6m3VzgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 19:45:03
(1 hour ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 19:24:22
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 19:21:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:21:53.615883 2026] [security2:error] [pid 14898:tid 14898] [client 34.125.191.177:9136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digitalsolutions.help.my-spec.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "ap8O0ZcjF4EiV-_lJyRsAgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-07 18:53:07
(2 hours ago)
34.125.191.177 - - [07/Sep/2026:14:53:06 -0400] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 50854 "https ...
show more
34.125.191.177 - - [07/Sep/2026:14:53:06 -0400] "GET /@fs/root/.env?raw?? HTTP/1.1" 404 50854 "https://ampanalytic.com/@fs/root/.env?raw??" "Mozilla/5.0 (compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)"
34.125.191.177 - - [07/Sep/2026:14:53:06 -0400] "GET /.env?raw?? HTTP/1.1" 404 50854 "https://ampanalytic.com/@fs/../.env?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
34.125.191.177 - - [07/Sep/2026:14:53:06 -0400] "GET /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw?? HTTP/1.1" 404 50854 "https://ampanalytic.com/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:29:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:29:48.695767 2026] [security2:error] [pid 14990:tid 14990] [client 34.125.191.177:2756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.thehomemailbox.com"] [uri "/@fs/root/.env"] [unique_id "ap8CnJO4_idho3Rl8gniaAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:08:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:08:45.698410 2026] [security2:error] [pid 29969:tid 29969] [client 34.125.191.177:59994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nothotmail.org"] [uri "/@fs/../../.env"] [unique_id "ap79rdbAdlU-BI0mzVHWkQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 17:47:21
(3 hours ago)
544 requests with url.path *.aws/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 17:21:48
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.191.177 (177.191.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:21:43.712154 2026] [security2:error] [pid 5605:tid 5720] [client 34.125.191.177:44248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.honeyled.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "ap7ypz2YA4KZBVkn7lNhVwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 17:20:34
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-07 17:15:52
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
mnsf
2026-09-07 17:05:28
(4 hours ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
Anonymous
2026-09-07 16:37:14
(4 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack