🇺🇸
wteiken
2026-09-07 02:51:24
(10 hours ago)
2026-09-06T22:51:22.864936-04:00 rocinante.teiken.net kernel: [642122.169057] syn_limit:IN=ens5 OUT= ...
show more
2026-09-06T22:51:22.864936-04:00 rocinante.teiken.net kernel: [642122.169057] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.59.29.129 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=12247 DF PROTO=TCP SPT=46740 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-06T22:51:22.870571-04:00 rocinante.teiken.net kernel: [642122.172449] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.59.29.129 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=36030 DF PROTO=TCP SPT=46746 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-06T22:51:23.084951-04:00 rocinante.teiken.net kernel: [642122.389067] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.59.29.129 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=26760 DF PROTO=TCP SPT=46750 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-06T22:51:23.228533-04:00 rocinante.teiken.net kernel: [642122.532648] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:a
...
show less
Port Scan
🇨🇭
backslash
2026-09-07 02:42:02
(10 hours ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
🇫🇷
Baking333
2026-09-07 02:33:50
(10 hours ago)
[redacted] 34.59.29.129 - - [07/Sep/2026:03:33:48 +0100] "GET /backend/.env HTTP/1.1" 302 6783 0/969 ...
show more
[redacted] 34.59.29.129 - - [07/Sep/2026:03:33:48 +0100] "GET /backend/.env HTTP/1.1" 302 6783 0/96938 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://[redacted]/)" [redacted] 34.59.29.129 - - [07/Sep/2026:03:33:48 +0100] "GET /config/.env HTTP/1.1" 302 6783 0/146669 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-07 02:01:26
(10 hours ago)
2.629 requests from abuseipdb.com blacklisted IP (1yr2mos1d)
Brute-Force
Bad Web Bot
🇩🇪
firestorm
2026-09-07 01:11:31
(11 hours ago)
34.59.29.129 - - [07/Sep/2026:03:11:30 +0200] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
34.59.2 ...
show more
34.59.29.129 - - [07/Sep/2026:03:11:30 +0200] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
34.59.29.129 - - [07/Sep/2026:03:11:30 +0200] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.59.29.129 - - [07/Sep/2026:03:11:30 +0200] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack
🇺🇸
Epimetheus
2026-09-07 00:52:24
(12 hours ago)
Zombie network / Bot scanner detected:
[GET] /.ssh/id_ed25519
[GET] /.profile
[GET] /.github/workfl ...
show more
Zombie network / Bot scanner detected:
[GET] /.ssh/id_ed25519
[GET] /.profile
[GET] /.github/workflows/deploy.yml
[GET] /graphql
[GET] /gcp-credentials.json
[GET] /dashboard/_payload.json
[GET] /api/.env.bak
[GET] /config.json.js
[GET] /.env.production.bak
[GET] /application.yml
[GET] /appsettings.json
[GET] /wp-config.php.old
[GET] /.env.swp
[GET] /.dockerenv
[GET] /images../.env
[GET] /@fs/root/.aws/credentials
[GET] /assets/manifest.json
[GET] /.env.production
[GET] /.env
[GET] /manifest.json
UA: Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)
show less
Bad Web Bot
Exploited Host
Web App Attack
🇩🇪
firestorm
2026-09-06 22:08:14
(14 hours ago)
34.59.29.129 - - [07/Sep/2026:00:08:13 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/ ...
show more
34.59.29.129 - - [07/Sep/2026:00:08:13 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.59.29.129 - - [07/Sep/2026:00:08:13 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
34.59.29.129 - - [07/Sep/2026:00:08:13 +0200] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
...
show less
Brute-Force
Web App Attack
🇨🇦
polycoda
2026-09-06 21:24:39
(15 hours ago)
🔥 VERY AGGRESSIVE SCANNER probed over 100 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
Anonymous
2026-09-06 19:57:37
(16 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.59.29.129 (US/United States/129.29.5 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.59.29.129 (US/United States/129.29.59.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 19:55:23
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.59.29.129 (129.29.59.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.59.29.129 (129.29.59.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:55:17.854314 2026] [security2:error] [pid 652645:tid 652645] [client 34.59.29.129:44882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cyber507.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cyber507.net"] [uri "/rclone.conf"] [unique_id "ap3FJfG0Pdqeucc_UFcJ3wAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
rh24
2026-09-06 19:30:18
(17 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.59.29.129 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.59.29.129 (US/United States/129.29.59.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 18:33:06
(18 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.59.29.129 (129.29.59.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 34.59.29.129 (129.29.59.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:33:02.801548 2026] [security2:error] [pid 29564:tid 29564] [client 34.59.29.129:60576] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||rrevelations.revelatorium.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "rrevelations.revelatorium.com"] [uri "/api/fs/read"] [unique_id "ap2x3j-BbTzCoXx8vOM_FwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-06 17:54:53
(18 hours ago)
Common web attack from 34.59.29.129.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:25:20
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.59.29.129 (129.29.59.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.59.29.129 (129.29.59.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:25:14.044401 2026] [security2:error] [pid 16223:tid 16223] [client 34.59.29.129:60508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rongrapes.com"] [uri "/_nuxt/../.env"] [unique_id "ap2T6qEey6JMrLu75v76fAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 15:50:01
(21 hours ago)
Excessive multi-domain requests
Brute-Force