๐ต๐ฑ
nakordoni.eu
2026-09-29 14:00:11
(1 week ago)
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matc ...
show more
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matches. ISP: Google LLC (DE), Usage: Data Center/Web Hosting/Transit. Prior AbuseIPDB score at ban time: 66/100.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 13:05:35
(1 week ago)
Web probing (508 hits in 24h) on default-vhost,www.gerhuntjens.nl: sensitive-path scans and/or 404 b ...
show more
Web probing (508 hits in 24h) on default-vhost,www.gerhuntjens.nl: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:54:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.185.149.159 (159.149.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.149.159 (159.149.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:54:02.925380 2026] [security2:error] [pid 7099:tid 7099] [client 34.185.149.159:36652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.deepseasugar.com"] [uri "/.git/config"] [unique_id "arsMKly7auw1hDshIeH6-AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 03:55:47
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.185.149.159 (159.149.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.185.149.159 (159.149.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 23:55:40.162240 2026] [security2:error] [pid 18998:tid 18998] [client 34.185.149.159:48050] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||games.samelsner.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "games.samelsner.com"] [uri "/.env.bak"] [unique_id "arnlPH3lctKajM4E7biZcQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-09-28 02:51:52
(1 week ago)
34.185.149.159 - - [28/Sep/2026:04:51:33 +0200] "GET / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (Macintosh ...
show more
34.185.149.159 - - [28/Sep/2026:04:51:33 +0200] "GET / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "games.melroy.org" 0.001
34.185.149.159 - - [28/Sep/2026:04:51:33 +0200] "POST / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "games.melroy.org" 0.001
34.185.149.159 - - [28/Sep/2026:04:51:33 +0200] "POST / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "games.melroy.org" 0.000
34.185.149.159 - - [28/Sep/2026:04:51:33 +0200] "POST / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "games.melroy.org" 0.000
34.185.149.159 - - [28/Sep/2026:04:51:33 +0200] "POST / HTTP/1.1" 403 93 "-" "Mozilla/5.0 (Macintosh; Intel
...
show less
Web App Attack
๐ต๐ฑ
maciejka
2026-09-27 06:13:17
(1 week ago)
34.185.149.159 - - [27/Sep/2026:08:13:16 +0200] "GET /mailer/.env HTTP/1.1" 404 106 "-" "Mozilla/5.0 ...
show more
34.185.149.159 - - [27/Sep/2026:08:13:16 +0200] "GET /mailer/.env HTTP/1.1" 404 106 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.149.159 - - [27/Sep/2026:08:13:16 +0200] "GET /mail/.env HTTP/1.1" 404 104 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-09-25 21:59:38
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-24.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-25 16:12:40
(1 week ago)
34.185.149.159 - - [25/Sep/2026:11:12:38 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windo ...
show more
34.185.149.159 - - [25/Sep/2026:11:12:38 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.185.149.159
34.185.149.159 - - [25/Sep/2026:11:12:38 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.185.149.159
34.185.149.159 - - [25/Sep/2026:11:12:38 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.185.149.159
34.185.149.159 - - [25/Sep/2026:11:12:38 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.185.149.159
34.185.149.159 - - [25/Sep/2026:11:12:38 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64)
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-09-24 02:15:16
(2 weeks ago)
Scanning for exploits - /.env
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-24 01:37:18
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ง
consul.to
2026-09-24 01:28:37
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 10:08:41
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ง
consul.to
2026-09-21 21:25:07
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 17:55:03
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 08:01:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.185.149.159 (159.149.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.149.159 (159.149.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 04:01:36.674656 2026] [security2:error] [pid 1365:tid 1365] [client 34.185.149.159:55608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "llew.life"] [uri "/.git/config"] [unique_id "arDkYE4M3WekoVY_ecd3jQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack