🇩🇪
Bedios GmbH
2026-09-08 18:57:03
(23 minutes ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-08 17:44:07
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:44:01.183004 2026] [security2:error] [pid 1338:tid 1345] [client 34.125.221.125:61110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.frcconstruction.com"] [uri "/@fs/src/.env"] [unique_id "aqBJYX9dEOHe-hXfEiiEygAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 17:35:30
(1 hour ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-08 17:14:10
(2 hours ago)
(modsecurity) srv104 ModSecurity 34.125.221.125 (US/United States/125.221.125.34.bc.googleuserconten ...
show more
(modsecurity) srv104 ModSecurity 34.125.221.125 (US/United States/125.221.125.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇳🇱
Savvii
2026-09-08 17:10:42
(2 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:44:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:43:58.460554 2026] [security2:error] [pid 30288:tid 30288] [client 34.125.221.125:11600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.josephnine.com.evannine.com"] [uri "/@fs/.env.development"] [unique_id "aqA7ToPWhISlGmklVCsk0gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:21:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:21:02.009889 2026] [security2:error] [pid 30201:tid 30201] [client 34.125.221.125:21728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pitigliano.montepulciano.org"] [uri "/@fs/.env"] [unique_id "aqA17iBYAv5Rd7n3Hs8gOwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 16:06:15
(3 hours ago)
Scanning/Probing (25)
Brute-Force
Web App Attack
🇧🇪
taivas.nl
2026-09-08 16:02:11
(3 hours ago)
Bad_requests
Bad Web Bot
🇧🇷
Halux
2026-09-08 15:51:32
(3 hours ago)
34.125.221.125 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:35:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:35:54.018746 2026] [security2:error] [pid 8420:tid 8420] [client 34.125.221.125:21394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.dentsville398.org"] [uri "/@fs/.env"] [unique_id "aqArWib4_GSbjmfAj5gEdAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:59:05
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.221.125 (125.221.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:58:56.884283 2026] [security2:error] [pid 4982:tid 4982] [client 34.125.221.125:35912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.brbvip.com"] [uri "/@fs/.env"] [unique_id "aqAisHMzm900IrXbRp-YbQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-08 14:56:37
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
🇩🇪
FD-IX
2026-09-08 14:50:45
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-08 14:40:04
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack