🇺🇸
TPI-Abuse
2026-09-04 16:33:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:33:06.976481 2026] [security2:error] [pid 19994:tid 19994] [client 34.125.21.177:18258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.skulldump.com"] [uri "/@fs/root/.env"] [unique_id "aprywjp98-L-B83wbh5eQgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:33:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:33:06.672096 2026] [security2:error] [pid 15966:tid 15966] [client 34.125.21.177:4332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alhashim.com"] [uri "/@fs/.env"] [unique_id "aprWog54U5QhSHk2ZXJ8ogAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-04 14:29:30
(3 days ago)
Automatically blocked due to distributed attack
Hacking
Anonymous
2026-09-04 14:07:11
(3 days ago)
Bot / seems abusive / Apache connections: 27
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇫🇷
mail.avx.gr
2026-09-04 14:02:16
(3 days ago)
(nginxENVSCAN) nginx environment-file scanner detected from 34.125.21.177 (US/United States/Nevada/L ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 34.125.21.177 (US/United States/Nevada/Las Vegas/177.21.125.34.bc.googleusercontent.com)
show less
Hacking
🇫🇷
Lino Project
2026-09-04 13:03:52
(3 days ago)
34.125.21.177 - - [04/Sep/2026:15:03:49 +0200] "GET /.env.bak HTTP/1.1" 302 1029 "-" "Mozilla/5.0 Ap ...
show more
34.125.21.177 - - [04/Sep/2026:15:03:49 +0200] "GET /.env.bak HTTP/1.1" 302 1029 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; TelegramBot/1.0"
34.125.21.177 - - [04/Sep/2026:15:03:49 +0200] "GET /.env HTTP/1.1" 302 1021 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user) Chrome/109.0.6229.183 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:09:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:08:59.260407 2026] [security2:error] [pid 1329:tid 1329] [client 34.125.21.177:29442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.racomm.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apqmywgfanlmID7B1k-7CQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 09:50:45
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
GabrielJST
2026-09-04 09:44:53
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.125.21.177 (US/United States/177.21. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.125.21.177 (US/United States/177.21.125.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇸🇪
vaia.cloud
2026-09-04 07:45:03
(3 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
FD-IX
2026-09-04 06:31:28
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 06:18:02
(3 days ago)
Restricted File Access Attempt. Matched phrase "/@fs/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:40:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:40:06.918943 2026] [security2:error] [pid 2497:tid 2497] [client 34.125.21.177:8978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.webersource.com"] [uri "/@fs/root/.env"] [unique_id "appLphTtDiunUTqkUL94OAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-04 04:19:48
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:43:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.21.177 (177.21.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:43:11.222918 2026] [security2:error] [pid 6582:tid 6582] [client 34.125.21.177:17714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chyps.com"] [uri "/@fs/app/.env"] [unique_id "apo-T7rVDQ4-wUHD_6ouDgAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack