๐จ๐ญ
backslash
2026-09-23 13:12:00
(1 hour ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-09-22 16:19:15
(22 hours ago)
Excessive 404/403 errors
Brute-Force
๐ง๐ช
taivas.nl
2026-09-22 04:34:03
(1 day ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:06:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:06:35.056248 2026] [security2:error] [pid 20102:tid 20102] [client 34.85.112.158:40840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brianbrock.horsesaw.com"] [uri "/.git/config"] [unique_id "arH-yz-HmJxahaGiRaStRwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:27:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:27:30.379890 2026] [security2:error] [pid 28754:tid 28754] [client 34.85.112.158:40898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brewhaha.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "arHZgkFI2pV8gezy8xNSDgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-22 01:02:12
(1 day ago)
Bad_requests
Bad Web Bot
Anonymous
2026-09-21 23:07:41
(1 day ago)
34.85.112.158 - - [21/Sep/2026:18:07:36 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
34.85.112.158 - - [21/Sep/2026:18:07:36 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.68.119.87
34.85.112.158 - - [21/Sep/2026:18:07:37 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.68.118.196
34.85.112.158 - - [21/Sep/2026:18:07:37 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.68.119.87
34.85.112.158 - - [21/Sep/2026:18:07:38 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.68.118.196
34.85.112.158 - - [21/Sep/2026:18:07:38 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:04:53
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-20.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 20:17:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:17:05.592664 2026] [security2:error] [pid 12108:tid 12108] [client 34.85.112.158:57420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.tracybur.net"] [uri "/.git/config"] [unique_id "arGQwTkGGT4O_SDABG_DGgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:39:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:39:23.676326 2026] [security2:error] [pid 632214:tid 632214] [client 34.85.112.158:39524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.taxgroupsd.com"] [uri "/.git/config"] [unique_id "arGH6-aEHa-43ADn1JrIGQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:25:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.112.158 (158.112.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:25:20.610461 2026] [security2:error] [pid 7050:tid 7050] [client 34.85.112.158:44020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blogs.melton.space"] [uri "/.git/config"] [unique_id "arF2kEDTbUFtAMVTnloWbAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
zam
2026-09-21 05:07:53
(2 days ago)
34.85.112.158 - - [21/Sep/2026:05:07:46 +0000] "GET /.git/config HTTP/1.1" 404 81952
34.85.112.158 - ...
show more
34.85.112.158 - - [21/Sep/2026:05:07:46 +0000] "GET /.git/config HTTP/1.1" 404 81952
34.85.112.158 - - [21/Sep/2026:05:07:46 +0000] "GET /.env HTTP/1.1" 404 81952
34.85.112.158 - - [21/Sep/2026:05:07:47 +0000] "GET /.env.local HTTP/1.1" 404 81952
34.85.112.158 - - [21/Sep/2026:05:07:47 +0000] "GET /.env.production HTTP/1.1" 404 81952
34.85.112.158 - - [21/Sep/2026:05:07:48 +0000] "GET /.env.staging HTTP/1.1" 404 81952
{"log":"34.85.112.158 - - [21/Sep/2026:05:07:48 +0000] "GET /.env.development HTTP/1.1" 404 81952\n","s
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 03:50:05
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ซ๐ฎ
netman
2026-09-21 03:35:44
(2 days ago)
HTTP: 34.85.112.158 blocked because of 500 failures
...
Port Scan
Web App Attack
Anonymous
2026-09-21 03:24:36
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack