๐ซ๐ท
LiloBzH
2026-10-06 15:49:36
(1 hour ago)
34.139.147.205 - - [06/Oct/2026:17:49:27 +0200] "GET /.git/config HTTP/2.0" 403 107 "-" "Mozilla/5.0 ...
show more
34.139.147.205 - - [06/Oct/2026:17:49:27 +0200] "GET /.git/config HTTP/2.0" 403 107 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.139.147.205 - - [06/Oct/2026:17:49:28 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 200 1292 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.139.147.205 - - [06/Oct/2026:17:49:28 +0200] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 200 1292 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-06 15:42:56
(1 hour ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-06 15:27:15
(1 hour ago)
Web App Attack
Anonymous
2026-10-06 14:35:03
(2 hours ago)
Bot / scanning and/or hacking attempts: POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepe ...
show more
Bot / scanning and/or hacking attempts: POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_, POST /php-cgi/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 14:27:18
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-06 14:23:37
(2 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-10-06 14:12:46
(2 hours ago)
Web App Attack
Web App Attack
Anonymous
2026-10-06 13:22:58
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:42:48
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.139.147.205 (205.147.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.139.147.205 (205.147.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:42:42.064145 2026] [security2:error] [pid 24208:tid 24208] [client 34.139.147.205:47968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lesdwiniarczyk.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lesdwiniarczyk.com"] [uri "/z9x8c7v6b5-debug-trigger-lesdwiniarczyk.com"] [unique_id "asTesmhlAdaHPtgSZmPzCQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:08:05
(5 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.139.147.205 (205.147.139.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.139.147.205 (205.147.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:07:57.501336 2026] [security2:error] [pid 15767:tid 15767] [client 34.139.147.205:35428] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "lenukuhivabookings.com"] [uri "/z9x8c7v6b5-debug-trigger-lenukuhivabookings.com"] [unique_id "asTWjTghCghLiN20ntsuBQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-06 11:05:20
(5 hours ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
Anonymous
2026-10-06 10:51:06
(6 hours ago)
Blocked by ModSec and CSF
Port Scan
๐ฉ๐ช
ghostwarriors
2026-10-06 10:50:11
(6 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-06 10:49:37
(6 hours ago)
34.139.147.205 - - [06/Oct/2026:12:49:35 +0200] "GET /.env?import&raw HTTP/2.0" 403 320 "-" "Mozilla ...
show more
34.139.147.205 - - [06/Oct/2026:12:49:35 +0200] "GET /.env?import&raw HTTP/2.0" 403 320 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
34.139.147.205 - - [06/Oct/2026:12:49:34 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///proc/self/environ&environmentName=rsc HTTP/2.0" 404 43222 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.139.147.205 - - [06/Oct/2026:12:49:35 +0200] "GET /.env?import&url&inline HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36"
34.139.147.205 - - [06/Oct/2026:12:49:35 +0200] "GET /.env.local?raw HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.139.147.205 - - [06/Oct/2026:12:49:34 +0200] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/2.0" 404 43222 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.139.147.205 - - [06/Oct/2026:12:49
show less
Bad Web Bot
๐ฉ๐ฐ
HostingGroup
2026-10-06 10:46:54
(6 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 5. First blocked: 2026-10-06.
show less
Bad Web Bot
Web App Attack