🇩🇪
Nightreaver
2026-09-11 07:19:28
(11 minutes ago)
34.185.64.196 - - [11/Sep/2026:09:19:27 0200] "GET /.env.production HTTP/1.1" 404 563 "-" "Mozilla/ ...
show more
34.185.64.196 - - [11/Sep/2026:09:19:27 0200] "GET /.env.production HTTP/1.1" 404 563 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.185.64.196 - - [11/Sep/2026:09:19:27 0200] "GET /.env.staging HTTP/1.1" 404 563 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.185.64.196 - - [11/Sep/2026:09:19:27 0200] "GET /.env.development HTTP/1.1" 404 563 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.185.64.196 - - [11/Sep/2026:09:19:27 0200] "GET /.env.test HTTP/1.1" 404 563 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.185.64.196 - - [11/Sep/2026:09:19:27 0200] "GET /.env.remote HTTP/1.1" 404 563 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome[...]
show less
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-11 06:32:43
(58 minutes ago)
20 attempts against mh_ha-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:06:05
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.64.196 (196.64.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.64.196 (196.64.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:06:01.436410 2026] [security2:error] [pid 12622:tid 12622] [client 34.185.64.196:42986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ironsightsarmory.com"] [uri "/.git/config"] [unique_id "aqOMOerf6Xv05A1LQ1m0OwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 04:35:14
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.185.64.196 (196.64.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.185.64.196 (196.64.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:35:09.172633 2026] [security2:error] [pid 30585:tid 30585] [client 34.185.64.196:35772] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ironmountainsports.com"] [uri "/.git/config"] [unique_id "aqOE_YUExYBusLdoMsWD1QAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 03:58:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.64.196 (196.64.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.64.196 (196.64.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:58:00.011129 2026] [security2:error] [pid 4810:tid 4810] [client 34.185.64.196:58040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ironheadsofseo.com"] [uri "/.git/config"] [unique_id "aqN8SHGniOgpTDwBiXvsJAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 03:43:26
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
mnsf
2026-09-10 12:05:23
(19 hours ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 11:59:30
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.64.196 (196.64.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.64.196 (196.64.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 07:59:24.617035 2026] [security2:error] [pid 8144:tid 8144] [client 34.185.64.196:52198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kcmastercleaners.com"] [uri "/.git/config"] [unique_id "aqKbnJb3YKRYNZsum6pqvgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-10 11:32:47
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.185.64.196 (US/United States/196.64. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.185.64.196 (US/United States/196.64.185.34.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
LRob
2026-09-10 11:24:17
(20 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-10 11:24 UTC
show less
Hacking
Web App Attack
🇺🇸
KayCee
2026-09-10 10:37:53
(20 hours ago)
34.185.64.196 - - [10/Sep/2026:06:37:51 -0400] "GET /.git/config HTTP/1.1" 404 1649 "-" "Mozilla/5.0 ...
show more
34.185.64.196 - - [10/Sep/2026:06:37:51 -0400] "GET /.git/config HTTP/1.1" 404 1649 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.64.196 - - [10/Sep/2026:06:37:51 -0400] "GET /.env HTTP/1.1" 404 1649 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.64.196 - - [10/Sep/2026:06:37:51 -0400] "GET /.env.local HTTP/1.1" 404 1649 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.64.196 - - [10/Sep/2026:06:37:51 -0400] "GET /.env.production HTTP/1.1" 404 1649 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
34.185.64.196 - - [10/Sep/2026:06:37:52 -0400] "GET /.env.staging HTTP/1.1" 404 1649 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
...
show less
Web App Attack
🇧🇾
lns.bz
2026-09-10 10:24:43
(21 hours ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
melroy89
2026-09-10 08:56:04
(22 hours ago)
34.185.64.196 - - [10/Sep/2026:10:55:57 +0200] "GET /.git/config HTTP/1.1" 403 524 "-" "Mozilla/5.0 ...
show more
34.185.64.196 - - [10/Sep/2026:10:55:57 +0200] "GET /.git/config HTTP/1.1" 403 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "kbin.melroy.org" 0.001
34.185.64.196 - - [10/Sep/2026:10:55:57 +0200] "GET /.env HTTP/1.1" 403 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "kbin.melroy.org" 0.000
34.185.64.196 - - [10/Sep/2026:10:55:57 +0200] "GET /.env.local HTTP/1.1" 403 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "kbin.melroy.org" 0.000
34.185.64.196 - - [10/Sep/2026:10:55:57 +0200] "GET /.env.production HTTP/1.1" 403 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "kbin.melroy.org" 0.000
34.185.64.196 - - [10/Sep/2026:10:55:57 +0200] "GET /.env.staging HTTP/1.1" 403 524 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36
...
show less
Web App Attack
🇺🇸
mccsoft.io
2026-09-10 07:27:35
(1 day ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 05:55:58
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack