๐ณ๐ฑ
oisecnet
2026-10-01 21:01:45
(12 hours ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-10-01. 343 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-10-01. 343 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐ซ๐ท
chrisj
2026-10-01 07:17:27
(1 day ago)
2026-10-01T07:17:26.679303+00:00 www.diamondaviators.net throttler[772]: Throttle IP 34.159.196.139 ...
show more
2026-10-01T07:17:26.679303+00:00 www.diamondaviators.net throttler[772]: Throttle IP 34.159.196.139 with 25 denials
...
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2026-10-01 07:09:49
(1 day ago)
34.159.196.139 - - [01/Oct/2026:09:09:49 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0 ...
show more
34.159.196.139 - - [01/Oct/2026:09:09:49 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15902 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.159.196.139 - - [01/Oct/2026:09:09:49 +0200] "GET /84nnh9nipwnu8qf5kmlx HTTP/2.0" 404 15902 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.159.196.139 - - [01/Oct/2026:09:09:49 +0200] "GET /q5zljcu6thhae8li7tq9 HTTP/2.0" 404 15902 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
34.159.196.139 - - [01/Oct/2026:09:09:49 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 15902 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
...
show less
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-10-01 06:35:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-01 04:56:20
(1 day ago)
[Thu Oct 01 06:56:20.149658 2026] [security2:error] [pid 4044051:tid 4044057] [client 34.159.196.139 ...
show more
[Thu Oct 01 06:56:20.149658 2026] [security2:error] [pid 4044051:tid 4044057] [client 34.159.196.139:53994] [client 34.159.196.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mail10.mrman.net"] [uri "/"] [unique_id "ar3n9A46HnNaY3CO2d9IggAAAIQ"]
[Thu Oct 01 06:56:20.292102 2026] [security2:error] [pid 4044051:tid 4044067] [client 34.159.196.139:53994] [client 34.159.196.139] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 03:18:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.159.196.139 (139.196.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.196.139 (139.196.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:18:11.742750 2026] [security2:error] [pid 9734:tid 10139] [client 34.159.196.139:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthtravel.net"] [uri "/web.config"] [unique_id "ar3Q81ummIfII6loyhNsYAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-10-01 03:04:00
(1 day ago)
Web attack. 34.159.196.139 - - [01/Oct/2026:05:03:59 +0200] "GET /auth/login HTTP/2.0" 404 20 "-" "M ...
show more
Web attack. 34.159.196.139 - - [01/Oct/2026:05:03:59 +0200] "GET /auth/login HTTP/2.0" 404 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
34.159.196.139 - - [01/Oct/2026:05:03:59 +0200] "GET /admin/login HTTP/2.0" 404 20 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
show less
Web App Attack
๐ซ๐ท
โจ
2026-10-01 02:17:12
(1 day ago)
Domain : creityhall.net
Rule : env
2026-10-01 02:15:44 217.194.212.111 GET /admin/.env - 443 - 34.15 ...
show more
Domain : creityhall.net
Rule : env
2026-10-01 02:15:44 217.194.212.111 GET /admin/.env - 443 - 34.159.196.139 HTTP/2.0 CCBot/2.0 (https://commoncrawl.org/faq/) - creityhall.net 404 0 0 6752 365 156 - -
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-01 01:50:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.159.196.139 (139.196.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.196.139 (139.196.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:50:52.167089 2026] [security2:error] [pid 17858:tid 17858] [client 34.159.196.139:37720] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alphazeta.net|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alphazeta.net"] [uri "/config/master.key"] [unique_id "ar28fCKGbPd0uAxRdE7J2wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-01 01:32:56
(1 day ago)
Remote Command Execution: Direct Unix Command Execution. Pattern match "(?i)(?:^|b (932250-195)
Hacking
๐ณ๐ฑ
ConsulHosting
2026-10-01 01:12:51
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 01:12:15
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
cmbplf
2026-10-01 00:03:21
(1 day ago)
2.707 requests from abuseipdb.com blacklisted IP (11mos2d9h)
Brute-Force
Bad Web Bot
๐ฉ๐ช
s@ch@
2026-09-30 21:30:02
(1 day ago)
Jail: plesk-modsecurity | Web application attack (Plesk ModSecurity)
Web App Attack
๐ฉ๐ช
rh24
2026-09-30 19:23:47
(1 day ago)
(badbots) Bad bot user-agent [redacted] from 34.159.196.139 (DE/Germany/139.196.159.34.bc.googleuser ...
show more
(badbots) Bad bot user-agent [redacted] from 34.159.196.139 (DE/Germany/139.196.159.34.bc.googleusercontent.com)
show less
Hacking