🇫🇮
mnazibo
2026-09-09 20:00:04
(6 minutes ago)
Date: 09/Sep/2026 22:51:10 | Reported IP: 34.177.101.93 mod_security | id: 930100 930110 930130 9301 ...
show more
Date: 09/Sep/2026 22:51:10 | Reported IP: 34.177.101.93 mod_security | id: 930100 930110 930130 930140 | SG/group.my_domain/- | Connections: 181 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /admin/.env; /.anthropic/config.json; /api/.env; /app-config.json; /app/.env; /assets../.env; /.aws/config; /.aws/credentials; /aws.env; /.azure/credentials; /backend/.env; /.claude/settings.json; /.codex/config.toml; /.config/anthropic/credentials/default.json; /config/database.yml; /config/.env; /.config/gcloud/application_default_credentials.json; /config.json; /config.php.bak; /config/secrets.yml; /core/.env; /credentials.json; /.cursor/mcp.json; /docker-compose.yaml; /docker-compose.yml; /.docker/config.json; /.docker/.env; /docker/.env; /.env.backup; /.env.bak; /.env.development; /.env.example; /.env.local; /.env.old; /.env.production; /.env.staging; /.env.swp; /firebase-config.json; /firebase-credentials.json; /frontend/.env; /@fs/..%252f..
show less
SQL Injection
Brute-Force
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-09 19:50:01
(16 minutes ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
todix
2026-09-09 18:17:31
(1 hour ago)
Web App Attack Exploid from 34.177.101.93
Web App Attack
🇮🇩
sockominfo
2026-09-09 18:00:53
(2 hours ago)
Active Response: IP 34.177.101.93 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: ...
show more
Active Response: IP 34.177.101.93 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 40%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇩🇪
rh24
2026-09-09 17:18:53
(2 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.177.101.93 (SG/Si ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 34.177.101.93 (SG/Singapore/93.101.177.34.bc.googleusercontent.com)
show less
Bad Web Bot
🇮🇩
sockominfo
2026-09-09 17:00:09
(3 hours ago)
Active Response: IP 34.177.101.93 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Rep ...
show more
Active Response: IP 34.177.101.93 Blocked via Firewall Drop. Threat Score: 0/10 (INFORMATIONAL). Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
🇨🇭
zynex
2026-09-09 16:07:33
(3 hours ago)
URL Probing: /@fs/root/.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:58:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:58:40.536241 2026] [security2:error] [pid 29541:tid 29541] [client 34.177.101.93:10310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.buggyshop.org"] [uri "/@fs/app/.env"] [unique_id "aqGCMMXMSQkysvB1ukDRhwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:02:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:02:04.508302 2026] [security2:error] [pid 24084:tid 24084] [client 34.177.101.93:29044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.voidpope.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqF07BoBjyB2db_zSBUz4AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-09 13:44:31
(6 hours ago)
Try to access /@fs/app/.env?raw??
Web App Attack
🇺🇸
Victor López
2026-09-09 13:44:20
(6 hours ago)
new.vpardilalaw.com 34.177.101.93 - - [09/Sep/2026:08:44:19 -0500] "GET /@fs/app/.env?raw?? HTTP/1.1 ...
show more
new.vpardilalaw.com 34.177.101.93 - - [09/Sep/2026:08:44:19 -0500] "GET /@fs/app/.env?raw?? HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)" -
new.vpardilalaw.com 34.177.101.93 - - [09/Sep/2026:08:44:19 -0500] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" -
new.vpardilalaw.com 34.177.101.93 - - [09/Sep/2026:08:44:19 -0500] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Claude-User/1.0; [email protected] )" -
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:59:56
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:59:50.039405 2026] [security2:error] [pid 24204:tid 24204] [client 34.177.101.93:53074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.leonardodecaprio.com"] [uri "/@fs/../.env"] [unique_id "aqFKNnkzEW-fHbR7NKDHKAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:41:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:41:31.332919 2026] [security2:error] [pid 28493:tid 28493] [client 34.177.101.93:28768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.movierebuspuzzles.com"] [uri "/@fs/src/.env"] [unique_id "aqFF6ytEiKH_xqyO-Ow6fAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
nomzamo
2026-09-09 11:36:44
(8 hours ago)
Fail2Ban reported: nginx-badbots
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 10:11:33
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.177.101.93 (93.101.177.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 06:11:27.870800 2026] [security2:error] [pid 20995:tid 20995] [client 34.177.101.93:9880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vc1.com"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252fapp/.env"] [unique_id "aqEwz9j_LBRDo-oqkNwwggAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack