Anonymous
2026-09-08 11:07:15
(1 hour ago)
34.126.172.5 - - [08/Sep/2026:13:07:14 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 117 "https://www.sc ...
show more
34.126.172.5 - - [08/Sep/2026:13:07:14 +0200] "GET /@fs/.env?raw?? HTTP/1.1" 403 117 "https://www.schmittel-sys.de/@fs/.env?raw??" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.5; rv:127.1) Gecko/20100101 Firefox/127.1; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-08 10:07:40
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:43:31
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:43:26.179847 2026] [security2:error] [pid 7286:tid 7286] [client 34.126.172.5:7130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "network22.net"] [uri "/@fs/src/.env"] [unique_id "ap_YvgyOX5cW0EZkjWGaGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 09:39:16
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
palzer.IT
2026-09-08 09:06:37
(3 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 34.126.172.5 - - [08/Sep/2026:11:06:22 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 34.126.172.5 - - [08/Sep/2026:11:06:22 +0200] GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? [DOMAIN_REMOVED] 403 6652 [DOMAIN_REMOVED] Mozilla/5.0 (Linux; Android 13; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Amzn-SearchBot/1.0; +[DOMAIN_REMOVED] Chrome/151.0.3367.114 Mobile Safari/537.36
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 07:40:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:40:52.861809 2026] [security2:error] [pid 3818:tid 3818] [client 34.126.172.5:54910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kalvannastudios.com"] [uri "/@fs/.env"] [unique_id "ap-8BIW98XFq-WchNLvjwAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
nadnitin
2026-09-08 07:36:10
(5 hours ago)
Automated trigger via Nginx Police. Reason: IP-SCANNER. Trigger Log: 34.126.172.5 - - [08/Sep/2026:1 ...
show more
Automated trigger via Nginx Police. Reason: IP-SCANNER. Trigger Log: 34.126.172.5 - - [08/Sep/2026:13:06:09 +0530] "GET / HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Port Scan
🇬🇧
consul.to
2026-09-08 07:32:58
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Site.eu
2026-09-08 07:19:36
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 07:04:09
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:04:01.179666 2026] [security2:error] [pid 14299:tid 14299] [client 34.126.172.5:19910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eatinnola.anthonyjoseph.us"] [uri "/@fs/app/.env"] [unique_id "ap-zYefVqEdkabv6ZXfvYgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 06:21:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.126.172.5 (5.172.126.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:21:25.469811 2026] [security2:error] [pid 2461:tid 2461] [client 34.126.172.5:2090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.njoyquilts.com"] [uri "/@fs/.env"] [unique_id "ap-pZSfuJ446_BNjBH6RGQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-08 05:40:43
(7 hours ago)
[TueSep0807:40:37.1102892026][security2:error][pid1163932:tid1164054][client34.126.172.5:0]ModSecuri ...
show more
[TueSep0807:40:37.1102892026][security2:error][pid1163932:tid1164054][client34.126.172.5:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"/etc/passwd\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"141\"][id\"347009\"][rev\"1\"][msg\"Atomicorp.comWAFRules:ProtectedFileaccessdenied\"][severity\"CRITICAL\"][hostname\"cpanel.bicycleambulance.ch\"][uri\"/@fs/etc/passwd\"][unique_id\"ap-f1TyuU3hdGzp1DKVdTAAAAQs\"]
show less
Port Scan
Brute-Force
Web App Attack
🇩🇪
macrob
2026-09-08 05:18:53
(7 hours ago)
2026/09/08 05:18:52 [error] 3640629#3640629: *569377731 access forbidden by rule, client: 34.126.172 ...
show more
2026/09/08 05:18:52 [error] 3640629#3640629: *569377731 access forbidden by rule, client: 34.126.172.5, server: 100fs.org, request: "GET /@fs/root/.env?raw?? HTTP/1.1", host: "100fs.org"
2026/09/08 05:18:52 [error] 3640629#3640629: *569377732 access forbidden by rule, client: 34.126.172.5, server: 100fs.org, request: "GET /@fs/src/.env?raw?? HTTP/1.1", host: "100fs.org"
2026/09/08 05:18:52 [error] 3640629#3640629: *569377733 access forbidden by rule, client: 34.126.172.5, server: 100fs.org, request: "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/1.1", host: "100fs.org"
...
show less
Web App Attack
🇫🇷
dynamix
2026-09-08 04:41:04
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇸🇪
vaia.cloud
2026-09-08 04:20:03
(8 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack