🇵🇫
www.gregorymariani.com
2026-09-06 15:31:12
(1 hour ago)
34.156.189.68 - - [06/Sep/2026:15:31:10 +0000] "GET /.env.local HTTP/1.1" 404 4106 "-" "Mozilla/5.0 ...
show more
34.156.189.68 - - [06/Sep/2026:15:31:10 +0000] "GET /.env.local HTTP/1.1" 404 4106 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 648 0.005 [default-techdata-service-80] [] 10.244.73.7:3000 4106 0.004 404 088d51037ae80b3e0ec0d277ae031308
34.156.189.68 - - [06/Sep/2026:15:31:10 +0000] "GET /.env.old HTTP/1.1" 404 4106 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 662 0.003 [default-techdata-service-80] [] 10.244.73.7:3000 4106 0.003 404 92dd26d4dff10bb70cd21abcd8501344
34.156.189.68 - - [06/Sep/2026:15:31:10 +0000] "GET /admin/.env HTTP/1.1" 404 4106 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 655 0.003 [default-techdata-service-80] [] 10.244.73.7:3000 4106 0.003 404 7e8762f4eb64f5371f450b371652f7ea
34.156.189.68 - - [06/Sep/2026:15:31:11 +0000] "GET /.env.example HTTP/1.1" 404 4106 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 662 0.007 [default-techdata-service-80] [] 10.244.73.7:30
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:16:29
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.189.68 (68.189.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.189.68 (68.189.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:16:23.988236 2026] [security2:error] [pid 16771:tid 16771] [client 34.156.189.68:44460] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||firstlegend.info|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "firstlegend.info"] [uri "/rclone.conf"] [unique_id "ap11txTeH29gbIp9rrHiOgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 14:07:04
(2 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-09-06 13:35:36
(3 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
🇫🇷
/dev/null
2026-09-06 13:18:08
(3 hours ago)
Web attack | malicious scanning detected.
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-06 12:52:18
(3 hours ago)
142 requests with url.path *.oci/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 12:27:06
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.156.189.68 (68.189.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.156.189.68 (68.189.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:27:00.693586 2026] [security2:error] [pid 26044:tid 26044] [client 34.156.189.68:35700] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crm.kircali.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crm.kircali.net"] [uri "/rclone.conf"] [unique_id "ap1cFP8MqKV8PGjnwE3FJQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
noise.agency
2026-09-06 12:12:42
(4 hours ago)
34.156.189.68 (BE/Belgium/68.189.156.34.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
Anonymous
2026-09-06 10:19:40
(6 hours ago)
Logfile match
Web App Attack
🇷🇴
clauss
2026-09-06 08:53:45
(7 hours ago)
34.156.189.68 - - [06/Sep/2026:11:53:43 +0300] "GET /rclone.conf HTTP/2.0" 403 129 "-" "Mozilla/5.0 ...
show more
34.156.189.68 - - [06/Sep/2026:11:53:43 +0300] "GET /rclone.conf HTTP/2.0" 403 129 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
34.156.189.68 - - [06/Sep/2026:11:53:44 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 404 21350 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇮🇹
VHosting
2026-09-06 08:35:03
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-06 08:30:11
(8 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.156.189.68 (BE/Belgium/68.189.156.34.bc.g ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.156.189.68 (BE/Belgium/68.189.156.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.156.189.68 - - [06/Sep/2026:10:30:10 +0200] "GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true HTTP/2.0" 406 317 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
34.156.189.68 - - [06/Sep/2026:10:30:10 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
34.156.189.68 - - [06/Sep/2026:10:30:10 +0200] "GET /.env.local?raw HTTP/2.0" 406 317 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
show less
Port Scan
Anonymous
2026-09-06 08:29:30
(8 hours ago)
Aggressive web scan
Web App Attack
🇩🇰
ScamAware
2026-09-06 08:16:55
(8 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 7. Unique request paths counted internally: 7. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
Anonymous
2026-09-06 08:13:54
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking