Anonymous
2026-09-04 00:31:26
(10 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
todix
2026-09-04 00:07:47
(34 minutes ago)
Web App Attack Exploid from 34.125.228.130
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-03 23:39:50
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-03 23:30:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:30:04.644732 2026] [security2:error] [pid 20461:tid 20461] [client 34.125.228.130:4728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.willmarksynthetics.com"] [uri "/@fs/.env"] [unique_id "apoC_NyoqVdT3D6yqEXa_QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 23:00:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:00:38.536614 2026] [security2:error] [pid 29131:tid 29131] [client 34.125.228.130:56850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gowithevergreen.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "apn8FgDUvJWGBFGp4gb2IQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 22:36:39
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:36:31.964281 2026] [security2:error] [pid 19617:tid 19617] [client 34.125.228.130:16828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.westernmassaa.net"] [uri "/@fs/app/.env"] [unique_id "apn2b9IGvIMv82UnrUQBywAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lacrimosa99
2026-09-03 22:26:10
(2 hours ago)
34.125.228.130 - - [04/Sep/2026:00:25:53 +0200] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1 ...
show more
34.125.228.130 - - [04/Sep/2026:00:25:53 +0200] "GET /@fs/home/admin/.aws/credentials?raw?? HTTP/1.1" 404 911 "-" "Mozilla/5.0 (compatible; GPTBot/1.4; +https://openai.com/gptbot)"
34.125.228.130 - - [04/Sep/2026:00:26:02 +0200] "GET /@fs/root/.config/gcloud/credentials.db?raw?? HTTP/1.1" 404 911 "-" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.6558.105 Safari/537.36; compatible; TelegramBot/1.0"
34.125.228.130 - - [04/Sep/2026:00:26:09 +0200] "GET /admin/.env HTTP/1.1" 404 911 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:127.9) Gecko/20100101 Firefox/127.9; compatible; Twitterbot/1.0"
...
show less
Web Spam
๐ซ๐ท
dynamix
2026-09-03 22:21:18
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-03 22:20:07
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-09-03 22:03:02
(2 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ฉ๐ช
4server
2026-09-03 22:01:35
(2 hours ago)
[FriSep0400:01:31.4763062026][security2:error][pid3474712:tid3474760][client34.125.228.130:0]ModSecu ...
show more
[FriSep0400:01:31.4763062026][security2:error][pid3474712:tid3474760][client34.125.228.130:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"lascalasagl.ch\"][uri\"/@fs/app/.env\"][unique_id\"apnuO8vb11xdeqNTK8gObwAAAEA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:41:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:41:51.633149 2026] [security2:error] [pid 17932:tid 17932] [client 34.125.228.130:1760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chalet-4saisons.com"] [uri "/@fs/root/.env"] [unique_id "apnpn0BxyIZnbcKff4luHQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:24:32
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.228.130 (130.228.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:24:25.623507 2026] [security2:error] [pid 5272:tid 5272] [client 34.125.228.130:49486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.modmove.com"] [uri "/@fs/app/.env"] [unique_id "apnlickPS9jY7OuZfPrdqgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-03 21:16:07
(3 hours ago)
1.113 requests with url.path *.aws/*
195 requests with url.path */auth.json
Brute-Force
Bad Web Bot
๐ณ๐ฑ
middelkoopcc
2026-09-03 21:02:01
(3 hours ago)
2026-09-03 23:00:28 GET /@fs/.env?raw?? [404] && 2026-09-03 23:00:28 GET /@fs/app/.env?raw?? [404] & ...
show more
2026-09-03 23:00:28 GET /@fs/.env?raw?? [404] && 2026-09-03 23:00:28 GET /@fs/app/.env?raw?? [404] && 2026-09-03 23:00:28 GET /@fs/proc/self/environ?raw?? [404] && 118 more within 20 minutes
show less
Web App Attack