๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-16 04:30:31
(1 hour ago)
[Tue Sep 15 22:30:29.103843 2026] [authz_core:error] [pid 73670:tid 140601785837120] [client 34.29.4 ...
show more
[Tue Sep 15 22:30:29.103843 2026] [authz_core:error] [pid 73670:tid 140601785837120] [client 34.29.40.139:36868] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Tue Sep 15 22:30:30.348948 2026] [authz_core:error] [pid 73670:tid 140601467045440] [client 34.29.40.139:36868] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Tue Sep 15 22:30:30.382566 2026] [authz_core:error] [pid 73670:tid 140601752266304] [client 34.29.40.139:36868] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 03:59:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (139.40.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (139.40.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:59:25.610979 2026] [security2:error] [pid 20547:tid 20547] [client 34.29.40.139:57826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.binfieldresources.com"] [uri "/.git/config"] [unique_id "aqoUHa3CXPt0IQqDAtBB1QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 00:20:55
(6 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /.git/config (+8 more) | ua: Mo ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /.git/config (+8 more) | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | 2026-09-16 00:20 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:18:59
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (139.40.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (139.40.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:18:54.456257 2026] [security2:error] [pid 11788:tid 11788] [client 34.29.40.139:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.betiqos.com"] [uri "/.git/config"] [unique_id "aqngbrY10evQdHW_NZuvrQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(6 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-15 23:24:55
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (139.40.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (139.40.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:24:51.156489 2026] [security2:error] [pid 22864:tid 22864] [client 34.29.40.139:35690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bestcommerciallaundry.net"] [uri "/.git/config"] [unique_id "aqnTw7nltUYQflvitvLHeAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 23:00:05
(7 hours ago)
Unauthorized SSH login attempts
Brute-Force
SSH
๐จ๐ญ
ca
2026-09-15 22:56:52
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
rh24
2026-09-15 22:23:39
(8 hours ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.29.40.139 (US/United States/139.40.29. ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.29.40.139 (US/United States/139.40.29.34.bc.googleusercontent.com)
show less
Hacking
๐ฉ๐ช
FD-IX
2026-09-15 22:23:27
(8 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 21:54:33
(8 hours ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.29.40.139 (US/United States/139.40.29.34. ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.29.40.139 (US/United States/139.40.29.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.29.40.139 - - [15/Sep/2026:23:54:28 +0200] "GET /.env HTTP/1.1" 406 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.29.40.139 - - [15/Sep/2026:23:54:28 +0200] "GET /.env.local HTTP/1.1" 406 4887 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.29.40.139 - - [15/Sep/2026:23:54:28 +0200] "GET /.env.production HTTP/1.1" 406 4886 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Port Scan
๐ณ๐ฑ
Mangelot Hosting
2026-09-15 21:41:50
(8 hours ago)
(modsecurity) srv104 ModSecurity 34.29.40.139 (US/United States/139.40.29.34.bc.googleusercontent.co ...
show more
(modsecurity) srv104 ModSecurity 34.29.40.139 (US/United States/139.40.29.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
abenage
2026-09-15 21:39:33
(8 hours ago)
34.29.40.139 - - [15/Sep/2026:15:39:32 -0600] "GET /phpinfo.php HTTP/1.1" 404 564 "-" "Mozilla/5.0 ( ...
show more
34.29.40.139 - - [15/Sep/2026:15:39:32 -0600] "GET /phpinfo.php HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 20:22:23
(10 hours ago)
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[mx02al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.29.40.139 - - [15/Sep/2026:22:22:22 +0200] "GET /.git/config HTTP/1.1" 404 1434 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
SysAdmin Dylan
2026-09-15 19:58:01
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (US/United States/139.40.29.34.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.40.139 (US/United States/139.40.29.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force