๐ฌ๐ง
poundawebsiteltd
2026-06-10 23:39:42
(1 minute ago)
Malicious activity in apache-honeypot. Evidence: [REDACTED_DOMAIN]:443 34.20.134.200 - - [11/Jun/202 ...
show more
Malicious activity in apache-honeypot. Evidence: [REDACTED_DOMAIN]:443 34.20.134.200 - - [11/Jun/2026:00:39:41 +0100] GET /api/config.json HTTP/1.1 301 3322 - Mozilla/5.0 (Linux; Android 9; Redmi Note 7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-10 20:32:40
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
4server
2026-06-10 20:09:45
(3 hours ago)
[WedJun1022:09:43.0979622026][security2:error][pid881355:tid881481][client34.20.134.200:0]ModSecurit ...
show more
[WedJun1022:09:43.0979622026][security2:error][pid881355:tid881481][client34.20.134.200:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.ksmstudio.ch.136-243-54-122.cpanel.site\"][uri\"/logfile\"][unique_id\"ainEhxznD08Y_pa1WII6WwAAARE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
bsoft.de
2026-06-10 19:51:17
(3 hours ago)
34.20.134.200 - - [10/Jun/2026:21:51:12 +0200] "GET /server/actuator/env HTTP/1.1" 301 169 "-" "Goog ...
show more
34.20.134.200 - - [10/Jun/2026:21:51:12 +0200] "GET /server/actuator/env HTTP/1.1" 301 169 "-" "Googlebot-Image/1.0"
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-06-10 17:52:03
(5 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 15:09:41
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.134.200 (200.134.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.134.200 (200.134.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 11:09:37.880964 2026] [security2:error] [pid 18411:tid 18411] [client 34.20.134.200:48916] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rondrez.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rondrez.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ail-MU_xrGRZbGaOZVYWAAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 07:07:55
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.20.134.200 (200.134.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.134.200 (200.134.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 03:07:49.166311 2026] [security2:error] [pid 414:tid 414] [client 34.20.134.200:52444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rallyattherock.billiardlifetapleague.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rallyattherock.billiardlifetapleague.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aikNRc_pR4NnabaJIi_jIwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 05:24:56
(18 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-06-10 04:24:12
(19 hours ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-10 02:37:48
(21 hours ago)
100 requests with url.path *compose.yml
Brute-Force
Bad Web Bot
๐จ๐ฆ
Mediashaker
2026-06-10 01:57:44
(21 hours ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 34.20.134.200 (US/United ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 34.20.134.200 (US/United States/200.134.20.34.bc.googleusercontent.com)
show less
Port Scan
๐บ๐ธ
mnsf
2026-06-10 00:07:56
(23 hours ago)
Abuse Detected (20)
Brute-Force
Web App Attack
Anonymous
2026-06-09 21:47:12
(1 day ago)
[redacted] 34.20.134.200 - - [09/Jun/2026:23:47:06 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 1663 ...
show more
[redacted] 34.20.134.200 - - [09/Jun/2026:23:47:06 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 16635 "-" "Mozilla/5.0 (Linux; Android 7.1.1; BBB100-1 Build/NMF26F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.125 Mobile Safari/537.36"
[redacted] 34.20.134.200 - - [09/Jun/2026:23:47:06 +0200] "GET /db.sql HTTP/1.1" 404 16635 "-" "Mozilla/5.0 (iPad; CPU OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Flipboard/4.2.48"
[redacted] 34.20.134.200 - - [09/Jun/2026:23:47:06 +0200] "GET /mysqldump.sql HTTP/1.1" 404 16635 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.87 Safari/537.36"
[redacted] 34.20.134.200 - - [09/Jun/2026:23:47:07 +0200] "GET /db.zip HTTP/1.1" 404 16635 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_3_3 like Mac OS X) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.0 Mobile/14G60 Safari/602.1"
[redacted] 34.20.134.200 - - [09/Jun/2026:23:47:07 +0200]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 19:20:18
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.20.134.200 (200.134.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.20.134.200 (200.134.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:20:12.353639 2026] [security2:error] [pid 26930:tid 26930] [client 34.20.134.200:45760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.healthyforyoullc.starrmail.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.healthyforyoullc.starrmail.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "aihnbGcSR7P0UITXj_YrGgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-09 17:42:03
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack