๐ช๐ธ
robotstxt
2026-09-24 21:38:59
(39 seconds ago)
152.42.215.34 - - [24/Sep/2026:21:38:49 +0000] "GET /.vscode HTTP/1.1" 403 29130 "https://search.yah ...
show more
152.42.215.34 - - [24/Sep/2026:21:38:49 +0000] "GET /.vscode HTTP/1.1" 403 29130 "https://search.yahoo.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36" "-" edge="152.42.215.34"
152.42.215.34 - - [24/Sep/2026:21:38:50 +0000] "GET /.well-known HTTP/1.1" 403 29131 "https://www.bing.com/" "Mozilla/5.0 (Linux; Android 15; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36 EdgA/136.0.0.0" "-" edge="152.42.215.34"
152.42.215.34 - - [24/Sep/2026:21:38:51 +0000] "GET /wp-admin/ HTTP/1.1" 403 31 "https://yandex.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" "-" edge="152.42.215.34"
152.42.215.34 - - [24/Sep/2026:21:38:52 +0000] "GET /wp-content/ HTTP/1.1" 403 29132 "https://www.bing.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15" "-" edge="152.42.215.34"
152.42.215.
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-24 16:49:48
(4 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.vscode | 2026-09-24 16:49 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-24 16:30:00
(5 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ซ๐ท
david.houstin
2026-09-24 16:12:57
(5 hours ago)
152.42.215.34 - - [24/Sep/2026:18:12:47 +0200] "GET /wp-json HTTP/1.1" 404 8249 "https://duckduckgo. ...
show more
152.42.215.34 - - [24/Sep/2026:18:12:47 +0200] "GET /wp-json HTTP/1.1" 404 8249 "https://duckduckgo.com/" "Mozilla/5.0 (Linux; Android 15; SM-S918B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Mobile Safari/537.36 OPR/109.0.0.0" 13641 -
152.42.215.34 - - [24/Sep/2026:18:12:47 +0200] "GET /wp-content/themes HTTP/1.1" 404 4533 "https://yandex.com/" "Mozilla/5.0 (Linux; Android 14; SM-G998B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Mobile Safari/537.36" 13433 -
152.42.215.34 - - [24/Sep/2026:18:12:47 +0200] "GET /wp-content/plugins HTTP/1.1" 404 4532 "https://yandex.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0" 9537 -
152.42.215.34 - - [24/Sep/2026:18:12:48 +0200] "GET /wp-content/uploads HTTP/1.1" 404 4533 "https://yandex.com/" "Mozilla/5.0 (Linux; Android 15; Pixel 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36 OPR/110.0.0.0" 16309 -
152.42.215.34 - - [24/Sep/2026:18:12:48 +0200] "GET
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2026-09-24 11:50:56
(9 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-json (Match: /wp-json)
show less
Hacking
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 10:13:47
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-24 09:43:35
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-09-23 06:53:25
(1 day ago)
152.42.215.34 - - [23/Sep/2026:06:53:16 +0000] "GET /.gitlab-ci HTTP/1.1" 403 6262 "https://www.bing ...
show more
152.42.215.34 - - [23/Sep/2026:06:53:16 +0000] "GET /.gitlab-ci HTTP/1.1" 403 6262 "https://www.bing.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36 Edg/135.0.0.0"
152.42.215.34 - - [23/Sep/2026:06:53:23 +0000] "GET /wp-content/cache HTTP/1.1" 404 26233 "https://duckduckgo.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
152.42.215.34 - - [23/Sep/2026:06:53:24 +0000] "GET /wp-content/upgrade/ HTTP/1.1" 403 2079 "https://search.yahoo.com/" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.5 Mobile/15E148 Safari/604.1"
152.42.215.34 - - [23/Sep/2026:06:53:24 +0000] "GET /wp-content/backup HTTP/1.1" 404 26175 "https://www.google.com/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 Edg/134.0.0.0"
152.42.215.34 - - [23/Sep/2026:06:53:25 +0
...
show less
Web App Attack
Exploited Host
๐ฆ๐บ
paulshipley.com.au
2026-09-22 18:12:33
(2 days ago)
[Wed Sep 23 04:12:32.538957 2026] [security2:error] [pid 278634] [client 152.42.215.34:58593] [clien ...
show more
[Wed Sep 23 04:12:32.538957 2026] [security2:error] [pid 278634] [client 152.42.215.34:58593] [client 152.42.215.34] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/.github"] [unique_id "arLFELdaTyxI770iWoOdcgAAAAE"], referer: https://www.google.com/
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-22 14:45:34
(2 days ago)
[Wed Sep 23 00:45:33.440567 2026] [security2:error] [pid 253898] [client 152.42.215.34:53538] [clien ...
show more
[Wed Sep 23 00:45:33.440567 2026] [security2:error] [pid 253898] [client 152.42.215.34:53538] [client 152.42.215.34] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/.gitlab-ci"] [unique_id "arKUjURyoqdD4JVTLlJSlwAAAAY"], referer: https://www.google.com/
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-22 12:02:38
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 152.42.215.34 (SG/Singapore/-): 2 i ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 152.42.215.34 (SG/Singapore/-): 2 in the last 3600 secs
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-22 11:51:45
(2 days ago)
[Tue Sep 22 21:51:44.808794 2026] [security2:error] [pid 240384] [client 152.42.215.34:49459] [clien ...
show more
[Tue Sep 22 21:51:44.808794 2026] [security2:error] [pid 240384] [client 152.42.215.34:49459] [client 152.42.215.34] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.id.au"] [uri "/.github"] [unique_id "arJr0Na_-Ut3djdifNnVBAAAABA"], referer: https://search.yahoo.com/
...
show less
Web App Attack
๐จ๐ฟ
Countryman
2025-07-05 09:13:55
(1 year ago)
repeated unauthorized connection attempts, host sweep, port scan
Port Scan
๐บ๐ธ
Rayulcifer
2025-07-04 13:26:30
(1 year ago)
152.42.215.34 - - [04/Jul/2025:08:26:06 -0500] "CONNECT abcsambalextrapedas.store:443:443 HTTP/1.1" ...
show more
152.42.215.34 - - [04/Jul/2025:08:26:06 -0500] "CONNECT abcsambalextrapedas.store:443:443 HTTP/1.1" 400 492 "-" "-"
152.42.215.34 - - [04/Jul/2025:08:26:30 -0500] "CONNECT abcsambalextrapedas.store:443:443 HTTP/1.1" 400 492 "-" "-"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
๐จ๐ฟ
Countryman
2025-07-04 01:58:39
(1 year ago)
repeated unauthorized connection attempts, host sweep, port scan
Port Scan