Anonymous
2026-09-20 23:33:32
(2 days ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 22:28:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:28:28.971531 2026] [security2:error] [pid 14205:tid 14285] [client 34.185.141.206:60174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iamfluff.com"] [uri "/.git/config"] [unique_id "arBeDMrOIQOG4IaldDQHCwAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
valornode
2026-09-20 22:02:24
(2 days ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-admin-interface-pr ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-admin-interface-probing | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: DE | Range: 34.184.0.0/14
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-20 20:43:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:43:32.143159 2026] [security2:error] [pid 2449:tid 2449] [client 34.185.141.206:43036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ialenti.com"] [uri "/.git/config"] [unique_id "arBFdIPEFOJrlpv2QNIflgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-20 20:33:28
(2 days ago)
[Mon Sep 21 06:33:27.644656 2026] [security2:error] [pid 25555] [client 34.185.141.206:44984] [clien ...
show more
[Mon Sep 21 06:33:27.644656 2026] [security2:error] [pid 25555] [client 34.185.141.206:44984] [client 34.185.141.206] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "iaki.com.au"] [uri "/"] [unique_id "arBDF0C60NpAxDZlajKJLwAAAA8"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:22:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:22:46.977136 2026] [security2:error] [pid 29492:tid 29492] [client 34.185.141.206:54062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iainrealtor.com"] [uri "/.git/config"] [unique_id "arBAlhXb7g1eR8bDJygGuwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-20 19:07:02
(3 days ago)
Malware host detected by rbl.malware.expert. RBL lookup of 206.141.185.34.rbl.malware.expert succeed ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 206.141.185.34.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-iad5-2)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 18:59:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:59:48.886744 2026] [security2:error] [pid 8915:tid 8940] [client 34.185.141.206:59474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iacsb.com"] [uri "/.git/config"] [unique_id "arAtJD0Pn0c29pFcBP_MMAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-20 18:49:04
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:42:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.141.206 (206.141.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:42:22.607217 2026] [security2:error] [pid 5928:tid 5928] [client 34.185.141.206:46038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "iacarbonell.com"] [uri "/.git/config"] [unique_id "arApDgBzxpc-jcX_pIiMpwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 18:40:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ง๐ช
Saec
2026-09-20 17:47:24
(3 days ago)
Jarvis auto-ban: Honeypot /.git/config via ia.saec.me [DE] ASN:Google LLC
Port Scan
Web App Attack
Anonymous
2026-09-20 17:31:19
(3 days ago)
34.185.141.206 - - [20/Sep/2026:17:31:04 +0000] "GET /.git/config HTTP/1.1" 502 552 "-" "Mozilla/5.0 ...
show more
34.185.141.206 - - [20/Sep/2026:17:31:04 +0000] "GET /.git/config HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.141.206 - - [20/Sep/2026:17:31:10 +0000] "GET /.env HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.141.206 - - [20/Sep/2026:17:31:13 +0000] "GET /.env.local HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.141.206 - - [20/Sep/2026:17:31:16 +0000] "GET /.env.production HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.141.206 - - [20/Sep/2026:17:31:19 +0000] "GET /.env.staging HTTP/1.1" 502 552 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Port Scan
Brute-Force
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-20 17:06:00
(3 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-20 16:08:02
(3 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice02,wa01,wa02]
Hacking
SQL Injection
Web App Attack