๐ง๐ช
boxed-it
2026-05-30 18:52:11
(2 weeks ago)
GET /config/.aws/credentials (Tarpitted for 1d15h8m29s, wasted 8.06MB)
Web App Attack
๐ฉ๐ช
Marc
2026-05-30 04:38:50
(2 weeks ago)
34.141.51.75 - - [30/May/2026:06:38:49 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 404 2982 "-" "iTunes/9. ...
show more
34.141.51.75 - - [30/May/2026:06:38:49 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 404 2982 "-" "iTunes/9.0.3 (Macintosh; U; Intel Mac OS X 10_6_2; en-ca)" 34.141.51.75 - - [30/May/2026:06:38:49 +0200] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 2983 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.154 Safari/537.36 OPR/20.0.1387.91" 34.141.51.75 - - [30/May/2026:06:38:49 +0200] "GET /.github/workflows/main.yml HTTP/1.1" 404 2982 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-30 01:43:04
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.141.51.75 (75.51.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.141.51.75 (75.51.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 21:43:00.669044 2026] [security2:error] [pid 27422:tid 27422] [client 34.141.51.75:49952] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.234|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.234"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahpApOpeJNX7pvtKl_Bf4gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-05-30 01:00:53
(2 weeks ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam
๐ณ๐ฟ
Antinson
2026-05-29 22:34:08
(2 weeks ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ง๐พ
lns.bz
2026-05-29 03:44:41
(2 weeks ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-05-29 03:36:02
(2 weeks ago)
1780025762 fail2ban apache-badbots 34.141.51.75 - - [29/May/2026:05:36:02 +0200] "GET /.ssh/id_rsa H ...
show more
1780025762 fail2ban apache-badbots 34.141.51.75 - - [29/May/2026:05:36:02 +0200] "GET /.ssh/id_rsa HTTP/1.1" 403 3775 "-" "EmailWolf 1.00"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-29 02:35:11
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.141.51.75 (75.51.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.51.75 (75.51.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 22:35:06.452095 2026] [security2:error] [pid 13697:tid 13697] [client 34.141.51.75:45062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.189"] [uri "/config/config.yml"] [unique_id "ahj7WnvX9tWdORN7mXH1_gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-29 02:10:11
(2 weeks ago)
Aggressive web scan
Web App Attack
๐ฌ๐ง
SilverZippo
2026-05-29 02:03:00
(2 weeks ago)
Web App Attack
Web App Attack
๐ฆ๐น
Markus Woegerbauer
2026-05-28 23:51:32
(2 weeks ago)
(CT) IP 34.141.51.75 (DE/Germany/75.51.141.34.bc.googleusercontent.com) found to have 764 connection ...
show more
(CT) IP 34.141.51.75 (DE/Germany/75.51.141.34.bc.googleusercontent.com) found to have 764 connections
show less
DDoS Attack
๐จ๐ฆ
Mediashaker
2026-05-28 23:18:16
(2 weeks ago)
(CT) IP 34.141.51.75 (DE/Germany/75.51.141.34.bc.googleusercontent.com) found to have 766 connection ...
show more
(CT) IP 34.141.51.75 (DE/Germany/75.51.141.34.bc.googleusercontent.com) found to have 766 connections
show less
DDoS Attack
๐บ๐ธ
tedmichalik.com
2026-05-28 21:32:49
(2 weeks ago)
34.141.51.75 - - [28/May/2026:17:32:34 -0400] "\x16\x03\x01" 400 517 "-" "-"
...
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-28 21:19:51
(2 weeks ago)
20 attempts against mh_ha-misbehave-ban on kale
Brute-Force
Bad Web Bot
Web App Attack