Anonymous
2026-05-23 16:46:52
(4 weeks ago)
(PERMBLOCK) 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercontent.com) has had more t ...
show more
(PERMBLOCK) 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ฏ๐ต
nhawsjones
2026-05-23 15:25:07
(4 weeks ago)
[Sun May 24 00:25:06.515355 2026] [authz_core:error] [pid 391759:tid 139783233844928] [client 34.135 ...
show more
[Sun May 24 00:25:06.515355 2026] [authz_core:error] [pid 391759:tid 139783233844928] [client 34.135.254.148:42110] AH01630: client denied by server configuration: /var/www/html/.htpasswd, referer: https://twitter.com/
...
show less
Brute-Force
Anonymous
2026-05-23 12:49:25
(4 weeks ago)
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:12:49:22 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:12:49:22 +0000] "GET /wp-config.php HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:12:49:23 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:12:49:23 +0000] "GET /.env.example HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:12:49:23 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-23 11:41:58
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.135.254.148 (148.254.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.254.148 (148.254.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 07:41:53.610981 2026] [security2:error] [pid 5654:tid 5654] [client 34.135.254.148:60468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jadeiteglobalholdings.com"] [uri "/.env"] [unique_id "ahGSgU0j-UCiVeXKd4vHiQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-23 11:17:51
(4 weeks ago)
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:11:17:45 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:11:17:46 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:11:17:47 +0000] "GET /wp-config.php HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:11:17:47 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:11:17:48 +0000] "GET /.env.example HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-23 10:12:12
(4 weeks ago)
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:10:12:09 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:10:12:09 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:10:12:10 +0000] "GET /wp-config.php HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:10:12:10 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:10:12:10 +0000] "GET /.env.example HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-23 08:51:02
(4 weeks ago)
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.135.254.148 (US/United States/148.254.135.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:08:50:56 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:08:50:57 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:08:50:57 +0000] "GET /wp-config.php HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:08:50:57 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 34.135.254.148 - - [23/May/2026:08:50:57 +0000] "GET /.env.example HTTP/1.1"
show less
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-05-22 22:02:10
(4 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-21.
show less
Web App Attack
SSH
Hacking
๐ฆ๐บ
artful
2026-05-22 05:08:00
(4 weeks ago)
Excessive errors, high load and multiple hits per second
Web App Attack
๐ซ๐ท
HerrWolf
2026-05-22 02:30:06
(4 weeks ago)
CrowdSec Detection: crowdsecurity/http-sensitive-files
Web App Attack
๐ฎ๐น
VHosting
2026-05-22 02:30:04
(4 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 20:19:57
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.135.254.148 (148.254.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.254.148 (148.254.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 16:19:50.915458 2026] [security2:error] [pid 25666:tid 25749] [client 34.135.254.148:42902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seracon.com.ec"] [uri "/.env"] [unique_id "ag9o5uLMYqhUNxp_5K_GkgAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 16:42:15
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.135.254.148 (148.254.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.254.148 (148.254.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 12:42:07.745313 2026] [security2:error] [pid 19032:tid 19032] [client 34.135.254.148:52494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharkfamily.com"] [uri "/.env"] [unique_id "ag8132tBDn7HmKLSBDuuNwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
nhawsjones
2026-05-21 15:12:28
(4 weeks ago)
[Fri May 22 00:12:27.343369 2026] [authz_core:error] [pid 3778069:tid 124819014129344] [client 34.13 ...
show more
[Fri May 22 00:12:27.343369 2026] [authz_core:error] [pid 3778069:tid 124819014129344] [client 34.135.254.148:58134] AH01630: client denied by server configuration: /var/www/html/.htpasswd
...
show less
Brute-Force