π¬π§
OptimusGO
2026-08-28 08:34:46
(2 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-28 09:34:46 UTC
Log evidence:
34.140.60.77 - - [28/Aug/2026:09:34:39 +0100] "GET / HTTP/1.1" 200 409 "-" "Mozilla/5.0 (Linux; Android 12; Pixel 6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Mobile Safari/537.36"
08/28/2026-09:34:44.637120 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 34.140.60.77:35380 -> 185.127.18.66:443
08/28/2026-09:34:44.637120 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 34.140.60.77:35380 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-28 07:22:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:22:02.474042 2026] [security2:error] [pid 26418:tid 26418] [client 34.140.60.77:46360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ji-technovation.com"] [uri "/@fs/.env"] [unique_id "apE3Gl0zb0NqbmB0opNbGgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Zundapper
2026-08-28 07:11:19
(4 hours ago)
34.140.60.77 - - [28/Aug/2026:09:11:14 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 178 "htt ...
show more
34.140.60.77 - - [28/Aug/2026:09:11:14 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 178 "https://www.idealmuseum.com/@fs/app/rootkey.csv?raw??" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.6537.191 Safari/537.36 Edg/131.0.6537.191; compatible; Claude-SearchBot/1.0; +https://www.anthropic.com/claude-searchbot"
34.140.60.77 - - [28/Aug/2026:09:11:14 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 117 "https://www.idealmuseum.com/@fs/root/rootkey.csv?raw??" "Mozilla/5.0 (compatible; LinkedInBot/1.0; +http://www.linkedin.com)"
34.140.60.77 - - [28/Aug/2026:09:11:14 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 117 "https://www.idealmuseum.com/@fs/etc/passwd?raw??" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
34.140.60.77 - - [28/Aug/2026:09:11:14 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 117 "https://www.idealmuseum.com/@fs/proc/self/en
...
show less
Web App Attack
Port Scan
π©πͺ
Hazzard
2026-08-28 06:06:48
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
ππΊ
DumaNet
2026-08-28 06:03:00
(5 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 06:52:33
Source IP: 34.140 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 06:52:33
Source IP: 34.140.60.77
Portion of the log(s):
34.140.60.77 - [28/Aug/2026:06:52:33 +0200] "GET /@fs/.env.production?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Mobile/15E148 Safari/604.1; compatible; TelegramBot/1.0"
34.140.60.77 - [28/Aug/2026:06:52:33 +0200] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
34.140.60.77 - [28/Aug/2026:06:52:33 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.140.60.77 - [28/Aug/2026:06:52:33 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) Apple
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 05:27:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:27:02.060373 2026] [security2:error] [pid 1821:tid 1821] [client 34.140.60.77:23798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.autodrive-away.com"] [uri "/@fs/.env"] [unique_id "apEcJhDmU1n5HRXiNu0zcAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
updown.io
2026-08-28 05:03:25
(6 hours ago)
{"level":"info","ts":1787893374.9309087,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1787893374.9309087,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.140.60.77","remote_port":"32050","client_ip":"34.140.60.77","proto":"HTTP/1.1","method":"GET","host":"status.ctf.viblo.asia","uri":"/","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"],"Accept":["*/*"],"Accept-Encoding":["gzip"]}},"bytes_read":0,"user_id":"","duration":0.000056098,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://status.ctf.viblo.asia/"]}}
{"level":"info","ts":1787893380.406664,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"34.140.60.77","remote_port":"62042","client_ip":"34.140.60.77","proto":"HTTP/1.1","method":"GET","host":"status.ctf.viblo.asia","uri":"/@fs/home/node/.aws/config?raw??","headers":{"Accept-Language":["en-US,en;q=0.9"],"Accept-Encoding":["gzi
...
show less
DDoS Attack
Web App Attack
ππΊ
DumaNet
2026-08-28 04:56:00
(6 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 23:17:54
Source IP: 34.140 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 23:17:54
Source IP: 34.140.60.77
Portion of the log(s):
34.140.60.77 - [27/Aug/2026:23:17:54 +0200] "GET /@fs/root/.azure/credentials?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko; compatible; Bytespider; +https://zhanzhang.toutiao.com/) Chrome/126.0.4320.190 Safari/537.36"
34.140.60.77 - [27/Aug/2026:23:17:54 +0200] "GET /@fs/app/credentials.json?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.8249.211 Safari/537.36 Edg/85.0.8249.211; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user"
34.140.60.77 - [27/Aug/2026:23:17:54 +0200] "GET /@fs/home/ubuntu/.azure/credentials?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 16_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.7 Mobile/15E148 Safari/604.1; compatible; Claude-User/1.0; +Cla
show less
Web App Attack
π¬π§
consul.to
2026-08-28 04:36:42
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
maxxsense
2026-08-28 04:35:52
(6 hours ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 34.140.60.77 (BE/Belgium ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 34.140.60.77 (BE/Belgium/77.60.140.34.bc.googleusercontent.com)
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-08-28 04:19:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:19:31.407908 2026] [security2:error] [pid 20967:tid 20967] [client 34.140.60.77:30422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.partybussantafe.com"] [uri "/@fs/../../.env"] [unique_id "apEMU2tjLXL4WFdt1FRYRAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-28 04:14:04
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π³π±
Site.eu
2026-08-28 04:12:32
(7 hours ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
Petros Stefanakis
2026-08-28 03:59:12
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.140.60.77 (BE/Belgium/77.60.140.34.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.140.60.77 (BE/Belgium/77.60.140.34.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-28 03:11:10
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.60.77 (77.60.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 23:11:04.698723 2026] [security2:error] [pid 19276:tid 19276] [client 34.140.60.77:1532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.icsubb.com"] [uri "/@fs/app/.env"] [unique_id "apD8SDAorrMFKWc3ulyTJAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack