๐ฌ๐ง
Aetherweb Ark
2026-06-11 21:17:27
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.148.214.107 (US/United States/107.214.148.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.148.214.107 (US/United States/107.214.148.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 19:26:13
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.148.214.107 (107.214.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.214.107 (107.214.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 15:26:07.387030 2026] [security2:error] [pid 395:tid 395] [client 34.148.214.107:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sistememail.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sistememail.com"] [uri "/db.sql"] [unique_id "aisLz8S9xyxrH67HzBXxEQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-06-11 18:02:41
(1 week ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 34.148.214.107 - - [11/Jun/2026: ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 34.148.214.107 - - [11/Jun/2026:19:02:39 +0100] GET /aws_credentials.json HTTP/1.1 403 2915 - Mozilla/5.0 (Linux; Android 9; EML-L09) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36
show less
Web App Attack
๐ซ๐ท
LRNP
2026-06-11 13:07:27
(1 week ago)
mirror2.urbanterror.info:443 34.148.214.107 - - [11/Jun/2026:13:07:26 +0000] "GET /app/actuator/env ...
show more
mirror2.urbanterror.info:443 34.148.214.107 - - [11/Jun/2026:13:07:26 +0000] "GET /app/actuator/env HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:25.0) Gecko/20100101 Firefox/25.0"
mirror2.urbanterror.info:443 34.148.214.107 - - [11/Jun/2026:13:07:26 +0000] "GET /api/actuator/configprops HTTP/1.1" 404 118 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) OPT/1.10.1 Mobile/15E148"
mirror2.urbanterror.info:443 34.148.214.107 - - [11/Jun/2026:13:07:26 +0000] "GET /backend/actuator/configprops HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.20 Safari/535.1"
mirror2.urbanterror.info:443 34.148.214.107 - - [11/Jun/2026:13:07:26 +0000] "GET /api/actuator/heapdump HTTP/1.1" 404 118 "-" "Nokia6100/1.0 (04.01) Profile/MIDP-1.0 Configuration/CLDC-1.0"
mirror2.urbanterror.info:443 34.148.214.107 - - [11/Jun/2026:13:07:26 +0000] "GET /v2/actuator/env HTTP/1.1" 404 181
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 09:45:10
(1 week ago)
Aggressive web scan
Web App Attack
๐ท๐บ
Reaper
2026-06-11 07:56:24
(1 week ago)
Repeated 404 errors from 34.148.214.107
Web App Attack
Anonymous
2026-06-11 07:11:13
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 34.148.214.107 (US/United States/107.21 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.148.214.107 (US/United States/107.214.148.34.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Site.eu
2026-06-11 06:03:42
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
cmbplf
2026-06-11 05:05:32
(1 week ago)
2.384 requests from abuseipdb.com blacklisted IP (7mos2w1d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
updown.io
2026-06-11 05:01:21
(1 week ago)
{"level":"info","ts":1781154080.8059835,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1781154080.8059835,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.148.214.107","remote_port":"58520","client_ip":"34.148.214.107","proto":"HTTP/1.1","method":"GET","host":"kjihkjilkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/api/configprops","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/36.0.1985.125 Safari/537.36"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]}},"bytes_read":0,"user_id":"","duration":0.000039345,"size":0,"status":308,"resp_headers":{"Connection":["close"],"Location":["https://kjihkjilkjihgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/api/configprops"],"Content-Type":[],"Server":["Caddy"]}}
{"level":"info","ts":1781154080.808272,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.148.214.107","remote_port":"58534","client_ip":"34.148.214.107","pr
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
paissangroup
2026-06-10 22:56:30
(1 week ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-06-10 17:08:37
(1 week ago)
(caddyscan) Scanner path probe from 34.148.214.107 (US/United States/107.214.148.34.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 34.148.214.107 (US/United States/107.214.148.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.148.214.107 - - [10/Jun/2026:17:08:31 +0000] "GET /actuator/logfile HTTP/1.1"
[REDACTED] 200 2627 34.148.214.107 - - [10/Jun/2026:17:08:31 +0000] "GET /v1/actuator/env HTTP/1.1"
[REDACTED] 200 2627 34.148.214.107 - - [10/Jun/2026:17:08:31 +0000] "GET /v2/actuator/heapdump HTTP/1.1"
[REDACTED] 200 2627 34.148.214.107 - - [10/Jun/2026:17:08:31 +0000] "GET /v2/actuator/env HTTP/1.1"
[REDACTED] 200 2627 34.148.214.107 - - [10/Jun/2026:17:08:31 +0000] "GET /v1/actuator/heapdump HTTP/1.1"
show less
Port Scan
๐ณ๐ฑ
Site.eu
2026-06-10 11:10:39
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-10 09:18:51
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.148.214.107 (107.214.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.148.214.107 (107.214.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 05:18:42.970243 2026] [security2:error] [pid 12428:tid 12428] [client 34.148.214.107:55670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.clipper1970.com.jimgrenier.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.clipper1970.com.jimgrenier.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aikr8gtGk2BXnnrhs4B9WQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wolfemium
2026-06-10 05:35:07
(1 week ago)
34.148.214.107 - - [10/Jun/2026:08:35:07 +0300] "GET /phpinfo.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 ...
show more
34.148.214.107 - - [10/Jun/2026:08:35:07 +0300] "GET /phpinfo.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3880.4 Safari/537.36"
34.148.214.107 - - [10/Jun/2026:08:35:07 +0300] "GET /php.php HTTP/1.1" 404 118 "-" "Mozilla/5.0 (Windows; U; Windows CE 5.1; rv:1.8.1a3) Gecko/20060610 Minimo/0.016"
34.148.214.107 - - [10/Jun/2026:08:35:07 +0300] "GET /debug.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36"
34.148.214.107 - - [10/Jun/2026:08:35:07 +0300] "GET /info.php HTTP/1.1" 404 118 "-" "HTC-ST7377/1.59.502.3 (67150) Opera/9.50 (Windows NT 5.1; U; en) UP.Link/6.3.1.17.0"
34.148.214.107 - - [10/Jun/2026:08:35:07 +0300] "GET /test.php HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36"
34.148.214.107 - - [10/Jun/2026:08:35:07
...
show less
DDoS Attack