๐ณ๐ฑ
homeshowdomain.nl
2026-08-31 22:01:27
(1 hour ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-30.
show less
Web App Attack
SSH
Hacking
๐ธ๐ช
nekopavel
2026-08-31 11:10:00
(12 hours ago)
34.154.60.135 - - [31/Aug/2026:13:09:58 +0200]"GET /.git/config HTTP/1.1" 404 178"-" autodiscover.ne ...
show more
34.154.60.135 - - [31/Aug/2026:13:09:58 +0200]"GET /.git/config HTTP/1.1" 404 178"-" autodiscover.neko.chat "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.001" "0.001""Milan" "IT"
34.154.60.135 - - [31/Aug/2026:13:09:58 +0200]"GET /.env HTTP/1.1" 404 178"-" autodiscover.neko.chat "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.001" "0.000""Milan" "IT"
34.154.60.135 - - [31/Aug/2026:13:09:58 +0200]"GET /.env.local HTTP/1.1" 404 178"-" autodiscover.neko.chat "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.001" "0.001""Milan" "IT"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 08:13:47
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:13:43.053799 2026] [security2:error] [pid 4142:tid 4142] [client 34.154.60.135:55768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.montymilburn.com"] [uri "/.git/config"] [unique_id "apU3t4mFZmqGjJ_1rj_euAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:38:28
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:38:21.930642 2026] [security2:error] [pid 15917:tid 15917] [client 34.154.60.135:46556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.microscopicpablo.com"] [uri "/.git/config"] [unique_id "apUhXYXur-IRxTHe7G4XuAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-30 17:38:51
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-30 16:29:05
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Mangelot Hosting
2026-08-30 15:45:12
(1 day ago)
(modsecurity) srv104 ModSecurity 34.154.60.135 (IT/Italy/135.60.154.34.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv104 ModSecurity 34.154.60.135 (IT/Italy/135.60.154.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-08-30 14:14:16
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 12:38:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 08:38:50.210630 2026] [security2:error] [pid 489:tid 489] [client 34.154.60.135:48782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.skincare.kalosgroups.com"] [uri "/.git/config"] [unique_id "apQkWiOlLkFpjPwbXNQItgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-08-30 12:07:18
(1 day ago)
WebAttack or semilar from 34.154.60.135
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-30 11:55:01
(1 day ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-08-30 10:59:20
(1 day ago)
[SunAug3012:59:13.4876692026][security2:error][pid1185861:tid1185993][client34.154.60.135:0]ModSecur ...
show more
[SunAug3012:59:13.4876692026][security2:error][pid1185861:tid1185993][client34.154.60.135:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.sisuconsulting.net.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apQNAeESm4xhczKJzbtPqwAAAVU\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-08-30 10:45:01
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 10:34:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.60.135 (135.60.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 06:34:46.892360 2026] [security2:error] [pid 7315:tid 7315] [client 34.154.60.135:38562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.siriusturbo.com.greenlight.us"] [uri "/.git/config"] [unique_id "apQHRhFJFGKAasOlvcNeywAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-08-30 10:09:18
(1 day ago)
[30/Aug/2026:12:09:11 +0200] 178808455181.545519 34.154.60.135 0 217.154.7.177 443
[30/Aug/2026:12:0 ...
show more
[30/Aug/2026:12:09:11 +0200] 178808455181.545519 34.154.60.135 0 217.154.7.177 443
[30/Aug/2026:12:09:12 +0200] 178808455212.525365 34.154.60.135 0 217.154.7.177 443
[30/Aug/2026:12:09:14 +0200] 178808455489.586055 34.154.60.135 0 217.154.7.177 443
[30/Aug/2026:12:09:15 +0200] 178808455563.310625 34.154.60.135 0 217.154.7.177 443
[30/Aug/2026:12:09:16 +0200] 178808455628.335910 34.154.60.135 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack