π³π±
homeshowdomain.nl
2026-09-17 22:04:25
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
π©πͺ
updown.io
2026-09-16 04:40:23
(4 days ago)
{"level":"info","ts":1789533621.1961434,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1789533621.1961434,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.158.103.191","remote_port":"36230","client_ip":"34.158.103.191","proto":"HTTP/1.1","method":"GET","host":"updown.arnext.net","uri":"/.env.development","headers":{"Connection":["keep-alive"],"Next-Action":["x"],"X-Nextjs-Request-Id":["f92dddfa"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"updown.arnext.net","ech":false}},"bytes_read":0,"user_id":"","duration":0.000155667,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1789533621.2073004,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.158.103.191","remote_port":"36230"
...
show less
DDoS Attack
Web App Attack
Anonymous
2026-09-15 22:30:06
(4 days ago)
suspicious request in access.log
Web App Attack
πͺπΈ
robotstxt
2026-09-15 20:10:59
(5 days ago)
34.158.103.191 - - [15/Sep/2026:20:10:41 +0000] "GET /.env HTTP/1.1" 403 15958 "-" "Mozilla/5.0 (X11 ...
show more
34.158.103.191 - - [15/Sep/2026:20:10:41 +0000] "GET /.env HTTP/1.1" 403 15958 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.158.103.191"
34.158.103.191 - - [15/Sep/2026:20:10:41 +0000] "GET /.env.local HTTP/1.1" 403 15958 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.158.103.191"
34.158.103.191 - - [15/Sep/2026:20:10:42 +0000] "GET /.env.production HTTP/1.1" 403 15958 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.158.103.191"
34.158.103.191 - - [15/Sep/2026:20:10:42 +0000] "GET /.env.staging HTTP/1.1" 403 15958 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.158.103.191"
34.158.103.191 - - [15/Sep/2026:20:10:42 +0000] "GET /.env.development HTTP/1.1" 403 15958 "-" "Mozilla/5.0 (X11; Linux x86
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 20:01:30
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:01:23.301063 2026] [security2:error] [pid 1931:tid 1931] [client 34.158.103.191:52888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.robotrodeo.chatsupply.us"] [uri "/.git/config"] [unique_id "aqmkE9h7eLEZXBZSD1TgtgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 17:45:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:45:13.867051 2026] [security2:error] [pid 10186:tid 10186] [client 34.158.103.191:51854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewillsmith.com"] [uri "/.git/config"] [unique_id "aqmEKXfMnorKlE20_o9OtQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
zynex
2026-09-15 17:14:50
(5 days ago)
URL Probing: /backend/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 16:16:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:16:47.533795 2026] [security2:error] [pid 26332:tid 26332] [client 34.158.103.191:42210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewhispertwins.com"] [uri "/.git/config"] [unique_id "aqlvb95NtPqtl-2sJJGqQAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 08:07:11
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:07:03.469612 2026] [security2:error] [pid 2022:tid 2022] [client 34.158.103.191:57754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogerproperties.com"] [uri "/.git/config"] [unique_id "aqj8pyw5YG_BLMXY9TlMMgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 07:02:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:02:23.417557 2026] [security2:error] [pid 518132:tid 518132] [client 34.158.103.191:40306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogerloft.com"] [uri "/.git/config"] [unique_id "aqjtf7Y4OspoGBczh2tXWgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-09-15 06:38:57
(5 days ago)
Multiple WAF Violations
Web App Attack
π¬π§
consul.to
2026-09-15 06:29:13
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 06:06:43
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:06:33.124387 2026] [security2:error] [pid 4144:tid 4144] [client 34.158.103.191:35360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogerheath.com"] [uri "/.git/config"] [unique_id "aqjgaWtbEmbTKMK6H75EKwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 05:51:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.103.191 (191.103.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:51:31.510105 2026] [security2:error] [pid 28023:tid 28023] [client 34.158.103.191:52850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rogerg.com"] [uri "/.git/config"] [unique_id "aqjc4-E53m75Pf2KRM3LCwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-15 05:42:50
(5 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack