Auto-ban: 315 malicious requests on 2026-06-10 (e.g., env/backup probes, brute-force, or error burst ...
show moreAuto-ban: 315 malicious requests on 2026-06-10 (e.g., env/backup probes, brute-force, or error bursts).
show less
(mod_security) mod_security (id:210730) triggered by 34.18.32.207 (QA/Qatar/207.32.18.34.bc.googleus ...
show more(mod_security) mod_security (id:210730) triggered by 34.18.32.207 (QA/Qatar/207.32.18.34.bc.googleusercontent.com): 5 in the last 60 secs
show less
{"level":"info","ts":1781138587.643636,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more{"level":"info","ts":1781138587.643636,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.18.32.207","remote_port":"54590","client_ip":"34.18.32.207","proto":"HTTP/1.1","method":"GET","host":"hgfedcfedgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io","uri":"/backend/actuator/configprops","headers":{"Connection":["close"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000069523,"size":0,"status":308,"resp_headers":{"Location":["https://hgfedcfedgc7402a95-6fc9-4756-b4e6-fa6c7eeb29c6.random.159.89.98.98.nip.io/backend/actuator/configprops"],"Content-Type":[],"Server":["Caddy"],"Connection":["close"]}}
{"level":"info","ts":1781138587.6458333,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.18.32.207","remote_port":"54560","client_ip":"34.18
...
show less
(mod_security) mod_security (id:949110) triggered by 34.18.32.207 (207.32.18.34.bc.googleusercontent ...
show more(mod_security) mod_security (id:949110) triggered by 34.18.32.207 (207.32.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:09:04.624084 2026] [security2:error] [pid 31069:tid 31069] [client 34.18.32.207:36110] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "manavamooreabookings.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ainEYJc8Qkr6eO8Fjg8iaQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
| [Dangerous/Qatar] Aggressive IP 34.18.32.207 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more| [Dangerous/Qatar] Aggressive IP 34.18.32.207 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
TCP SYN flood detected by MikroTik RouterOS filter (sustained half-open connection rate from single ...
show moreTCP SYN flood detected by MikroTik RouterOS filter (sustained half-open connection rate from single source). Source automatically blacklisted.
show less