Anonymous
2026-09-16 05:46:02
(2 days ago)
Bot / scanning and/or hacking attempts: GET /debug/pprof HTTP/2.0, GET /serviceAccountKey.json HTTP/ ...
show more
Bot / scanning and/or hacking attempts: GET /debug/pprof HTTP/2.0, GET /serviceAccountKey.json HTTP/2.0, GET /serverless.yml HTTP/2.0, GET /actuator/configprops HTTP/2.0, GET /.docker/config.json HTTP/2.0, GET /credentials.js HTTP/2.0, GET /server-status HTTP/2.0, GET /v1/onboarding/config?token= HTTP/2.0, GET /.htpasswd HTTP/2.0, GET /test.php HTTP/2.0, GET /_debugbar/open HTTP/2.0, GET /.ssh/id_ed25519 HTTP/2.0, GET /key.pem HTTP/2.0, [213/213] read: stream 0, , [202/202] read: stream 0, , [263/260] schedule: stream 525, GET /localhost.key, GET /id_rsa HTTP/2.0, [259/259] read: stream 0, , GET /id_ed25519 HTTP/2.0, GET /configuration.js HTTP/2.0, GET /userfiles?path=../../.env HTTP/2.0
show less
Hacking
Web App Attack
πΏπ¦
conure.sh
2026-09-16 04:28:20
(2 days ago)
csagent: score 19.8: spoofed crawler UA x1, secrets grab x1; 1 domain(s) in 7s
Web App Attack
π²π½
octageeks.com
2026-09-16 04:23:17
(2 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π¬π§
threewalls.co.uk
2026-09-16 04:17:07
(2 days ago)
Triggered bot honeypot on thegardenrange.co.uk. Ignored nofollow and disallow directives.
Fraud Orders
FTP Brute-Force
Brute-Force
Exploited Host
π³π±
Site.eu
2026-09-16 01:41:34
(2 days ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
niedson
2026-09-16 01:30:02
(2 days ago)
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.e ...
show more
Automated scanning for exposed secrets: repeated requests for multiple distinct credential paths (.env variants, .git metadata, .ssh private keys, .aws/credentials). Unsolicited. Reported automatically.
show less
Web App Attack
π¬π§
andypiper
2026-09-16 01:00:28
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
π²πΎ
Rizzy
2026-09-16 00:47:32
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-16 00:16:09
(2 days ago)
Blocked by ModSec and CSF
Port Scan
Anonymous
2026-09-15 23:37:08
(2 days ago)
34.26.164.224 - - [15/Sep/2026:18:37:07 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compat ...
show more
34.26.164.224 - - [15/Sep/2026:18:37:07 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 34.26.164.224
34.26.164.224 - - [15/Sep/2026:18:37:07 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" 34.26.164.224
34.26.164.224 - - [15/Sep/2026:18:37:07 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" 34.26.164.224
34.26.164.224 - - [15/Sep/2026:18:37:08 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 34.26.164.224
34.26.164.224 - - [15/Sep/2026:18:37:08 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" 34.26.164.224
34.26.164.224 -
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 21:36:09
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.26.164.224 (224.164.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.164.224 (224.164.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:36:03.302770 2026] [security2:error] [pid 6914:tid 6914] [client 34.26.164.224:35000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sierrablue.farm|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sierrablue.farm"] [uri "/rclone.conf"] [unique_id "aqm6Q-mlK1-A9zhLTozEMQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 20:38:19
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.26.164.224 (224.164.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.164.224 (224.164.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:15.788943 2026] [security2:error] [pid 23907:tid 23907] [client 34.26.164.224:45054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serranoscoffee.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serranoscoffee.com"] [uri "/z9x8c7v6b5-debug-trigger-serranoscoffee.com"] [unique_id "aqmst1SB0aBxigJ4rLGW-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 20:20:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.26.164.224 (224.164.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.164.224 (224.164.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:20:04.047785 2026] [security2:error] [pid 7098:tid 7098] [client 34.26.164.224:53376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sekelconsulting.com"] [uri "/.git/config"] [unique_id "aqmodHTGH2QlelCiv3Ul_AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 19:58:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.26.164.224 (224.164.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.26.164.224 (224.164.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:58:46.914797 2026] [security2:error] [pid 31613:tid 31613] [client 34.26.164.224:55426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoutmountaindistrict.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoutmountaindistrict.org"] [uri "/rclone.conf"] [unique_id "aqmjdkwsHrOEBB0_hqlaKgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
poundawebsiteltd
2026-09-15 19:37:54
(2 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.26.164. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.26.164.224 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.26.164.224 (US/United States/224.164.26.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack