๐บ๐ธ
BSG Webmaster
2026-07-30 07:00:08
(8 hours ago)
Port scanning (Port 443)
Port Scan
Hacking
๐ณ๐ฑ
tmiland
2026-07-30 06:57:06
(8 hours ago)
(nginx_404) Dot directory Honeypot Trap 34.158.171.226 (226.171.158.34.bc.googleusercontent.com): 2 ...
show more
(nginx_404) Dot directory Honeypot Trap 34.158.171.226 (226.171.158.34.bc.googleusercontent.com): 2 in the last 3600 secs; IP: 34.158.171.226; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.158.171.226 - - [30/Jul/2026:08:57:04 +0200] "GET /.aws/credentials HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)" 34.158.171.226 - - [30/Jul/2026:08:57:04 +0200] "GET /.git/HEAD HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)"
show less
Brute-Force
๐ซ๐ฎ
Christopher Hughes
2026-07-30 06:25:51
(9 hours ago)
34.158.171.226 - - [30/Jul/2026:07:25:50 +0100] "GET /.git/HEAD HTTP/2.0" 404 246 "-" "Mozilla/5.0 ( ...
show more
34.158.171.226 - - [30/Jul/2026:07:25:50 +0100] "GET /.git/HEAD HTTP/2.0" 404 246 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
2026-07-30 05:29:11
(10 hours ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 03:37:38
(11 hours ago)
114 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
๐ฌ๐ง
Aetherweb Ark
2026-07-30 03:21:06
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.158.171.226 (226.171.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.158.171.226 (226.171.158.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
JustMeHere
2026-07-30 03:20:16
(12 hours ago)
[Wed Jul 29 23:20:07.458035 2026] [security2:error] [pid 1301:tid 1350] [client 34.158.171.226:56634 ...
show more
[Wed Jul 29 23:20:07.458035 2026] [security2:error] [pid 1301:tid 1350] [client 34.158.171.226:56634] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "workspace.yorknation.com"] [uri "/.aws/config"] [unique_id "amrC5xpGy8Je12I35UWJxQAAANU"]
...
show less
Web App Attack
Anonymous
2026-07-30 03:12:22
(12 hours ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-07-30 02:31:38
(13 hours ago)
34.158.171.226 - - [30/Jul/2026:03:31:37 +0100] "GET /.aws/credentials HTTP/2.0" 404 246 "-" "Mozill ...
show more
34.158.171.226 - - [30/Jul/2026:03:31:37 +0100] "GET /.aws/credentials HTTP/2.0" 404 246 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ท
sthoyer.de
2026-07-30 02:16:39
(13 hours ago)
34.158.171.226 - - [30/Jul/2026:04:16:38 +0200] "GET /.aws/config HTTP/2" 302 495 "-" "Mozilla/5.0 A ...
show more
34.158.171.226 - - [30/Jul/2026:04:16:38 +0200] "GET /.aws/config HTTP/2" 302 495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] "
34.158.171.226 - - [30/Jul/2026:04:16:38 +0200] "GET /.aws/credentials HTTP/2" 302 495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] "
34.158.171.226 - - [30/Jul/2026:04:16:38 +0200] "GET /dashboard HTTP/2" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-07-30 01:52:41
(13 hours ago)
34.158.171.226 - - [30/Jul/2026:02:52:40 +0100] "GET /.hermes/auth.json HTTP/2.0" 404 246 "-" "Mozil ...
show more
34.158.171.226 - - [30/Jul/2026:02:52:40 +0100] "GET /.hermes/auth.json HTTP/2.0" 404 246 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐บ๐ธ
JustMeHere
2026-07-30 01:06:16
(14 hours ago)
[Wed Jul 29 21:06:11.071135 2026] [security2:error] [pid 1301:tid 1339] [client 34.158.171.226:40382 ...
show more
[Wed Jul 29 21:06:11.071135 2026] [security2:error] [pid 1301:tid 1339] [client 34.158.171.226:40382] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "api.yorknation.com"] [uri "/.aws/config"] [unique_id "amqjgxpGy8Je12I35UV4swAAAMo"]
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-30 00:28:38
(15 hours ago)
20 attempts against mh_ha-misbehave-ban on boron
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-07-30 00:15:10
(15 hours ago)
34.158.171.226 - - [30/Jul/2026:01:15:09 +0100] "GET /.s3cfg HTTP/2.0" 404 246 "-" "Mozilla/5.0 (com ...
show more
34.158.171.226 - - [30/Jul/2026:01:15:09 +0100] "GET /.s3cfg HTTP/2.0" 404 246 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-29 23:34:05
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack