🇫🇷
SpaceHost-Server
2026-09-06 22:19:11
(16 hours ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:55:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:55:03.740248 2026] [security2:error] [pid 21753:tid 21753] [client 34.20.202.77:36332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wisdomwfm.com"] [uri "/.env.dev"] [unique_id "apzkF88JVrHIAvnZuZH6DAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
AWW-Admin
2026-09-06 02:57:22
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.20.202.77 (US/United States/77.202.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.20.202.77 (US/United States/77.202.20.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 02:53:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:53:08.422782 2026] [security2:error] [pid 17403:tid 17403] [client 34.20.202.77:42822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "periodthreads.com"] [uri "/wp-config.php~"] [unique_id "apzVlKmHTxrzBGDzxlqmbQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:32:12
(1 day ago)
Blocked by firewall on hugin [443/tcp] | Rule: AbuseIPDB | SPT: 48918 | TTL: 64 | LEN: 60 | TOS: 0x0 ...
show more
Blocked by firewall on hugin [443/tcp] | Rule: AbuseIPDB | SPT: 48918 | TTL: 64 | LEN: 60 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇫🇷
masterguru
2026-09-06 02:31:57
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.20.202.77 (US/United States/77.202 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.20.202.77 (US/United States/77.202.20.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 02:28:32
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 01:51:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:51:50.974393 2026] [security2:error] [pid 12169:tid 12169] [client 34.20.202.77:39058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salernospizza.com"] [uri "/.env"] [unique_id "apzHNmf0Brf0pARzR3SHSAAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 01:36:44
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.production (+12 more) | 2026-09-06 01:36 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:09:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.77 (77.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:09:33.981039 2026] [security2:error] [pid 15279:tid 15279] [client 34.20.202.77:39978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dunningtons.com"] [uri "/wp-config.php.bak"] [unique_id "apy9TZohK6DfAST67pa_-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-06 01:01:47
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇺🇦
Olexiy Backend
2026-09-06 00:35:25
(1 day ago)
34.20.202.77
...
Bad Web Bot
Web App Attack
🇵🇱
lns.bz
2026-09-06 00:28:43
(1 day ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
🇩🇪
macrob
2026-09-06 00:13:36
(1 day ago)
2026/09/06 00:13:34 [error] 1902786#1902786: *561025459 access forbidden by rule, client: 34.20.202. ...
show more
2026/09/06 00:13:34 [error] 1902786#1902786: *561025459 access forbidden by rule, client: 34.20.202.77, server: infinsa.com, request: "GET /.env HTTP/2.0", host: "infinsa.com"
2026/09/06 00:13:34 [error] 1902782#1902782: *561025460 access forbidden by rule, client: 34.20.202.77, server: infinsa.com, request: "GET /.env.save HTTP/2.0", host: "infinsa.com"
2026/09/06 00:13:34 [error] 1902786#1902786: *561025461 access forbidden by rule, client: 34.20.202.77, server: infinsa.com, request: "GET /.env.dev HTTP/2.0", host: "infinsa.com"
...
show less
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH