๐ง๐ท
Peregrine
2026-06-04 03:13:33
(10 hours ago)
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET ...
show more
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/config HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.config/gcloud/credentials.db HTTP/1.1" 404 414
show less
Bad Web Bot
๐ง๐ท
Peregrine
2026-06-02 03:13:54
(2 days ago)
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET ...
show more
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/config HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.config/gcloud/credentials.db HTTP/1.1" 404 414
show less
Bad Web Bot
๐ง๐ท
Peregrine
2026-05-31 03:13:18
(4 days ago)
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET ...
show more
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/config HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.config/gcloud/credentials.db HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
ShadowWhisperer
2026-05-30 04:47:15
(5 days ago)
HTTP GET /actuator/env UA: Mozilla/5.0 (Linux; Android 9; Redmi Note 7) AppleWebKit/537.36
Web App Attack
๐ณ๐ฑ
SysAdmin Dylan
2026-05-30 03:25:17
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.181.213.38 (US/United States/38.213.181.34.b ...
show more
(mod_security) mod_security (id:210730) triggered by 34.181.213.38 (US/United States/38.213.181.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
๐ฉ๐ช
webanyone
2026-05-30 00:30:20
(5 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ง๐ท
Peregrine
2026-05-29 22:39:46
(5 days ago)
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET ...
show more
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/credentials HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.aws/config HTTP/1.1" 404 414
- 34.181.213.38 - - [29/May/2026:19:39:43 -0300] "GET /.config/gcloud/credentials.db HTTP/1.1" 404 414
show less
Bad Web Bot
๐ณ๐ฟ
Antinson
2026-05-29 22:34:08
(5 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ซ๐ท
dynamix
2026-05-29 02:38:58
(6 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-05-28 23:58:39
(6 days ago)
[Fri May 29 01:58:38.739877 2026] [authz_core:error] [pid 16317] [client 34.181.213.38:54384] AH0163 ...
show more
[Fri May 29 01:58:38.739877 2026] [authz_core:error] [pid 16317] [client 34.181.213.38:54384] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 29 01:58:38.792620 2026] [authz_core:error] [pid 15660] [client 34.181.213.38:54394] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 29 01:58:38.796290 2026] [authz_core:error] [pid 15774] [client 34.181.213.38:54412] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 21:35:34
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 34.181.213.38 (38.213.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.181.213.38 (38.213.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 17:35:28.049638 2026] [security2:error] [pid 1660:tid 1660] [client 34.181.213.38:57188] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.114|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.114"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahi1IAhvKgVNmn5NJaCExwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack