๐ฎ๐ฉ
Burayot
2026-09-01 13:02:50
(23 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.40.232.77 (AU/Australia/77.232.4 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.40.232.77 (AU/Australia/77.232.40.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-01 12:48:04
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ท๐ด
clauss
2026-09-01 12:38:17
(23 hours ago)
34.40.232.77 - - [01/Sep/2026:15:38:17 +0300] "GET /_ignition/health-check HTTP/2.0" 404 16541 "-" " ...
show more
34.40.232.77 - - [01/Sep/2026:15:38:17 +0300] "GET /_ignition/health-check HTTP/2.0" 404 16541 "-" "crusader-worker/1.0"
34.40.232.77 - - [01/Sep/2026:15:38:17 +0300] "GET /actuator/env HTTP/2.0" 404 16541 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 12:07:18
(1 day ago)
Try to access /.env
Web App Attack
๐ซ๐ท
ecode hosting
2026-09-01 10:16:05
(1 day ago)
Domain : agromersin.ru
Rule : hack
2026-09-01 10:15:33 10.100.1.20 GET /wp-config.php.bak - 80 - 34. ...
show more
Domain : agromersin.ru
Rule : hack
2026-09-01 10:15:33 10.100.1.20 GET /wp-config.php.bak - 80 - 34.40.232.77 HTTP/1.1 crusader-worker/1.0 - agromersin.ru 301 0 0 345 102 321 - -
show less
Hacking
SQL Injection
Brute-Force
๐ซ๐ท
masterguru
2026-09-01 09:48:14
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.40.232.77 (AU/Australia/77.232.40. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.40.232.77 (AU/Australia/77.232.40.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
COMAITE
2026-09-01 09:45:35
(1 day ago)
Suspicious URL access.
Web App Attack
๐ฉ๐ช
webanyone
2026-09-01 06:32:48
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:07:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.232.77 (77.232.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.232.77 (77.232.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:07:12.914867 2026] [security2:error] [pid 8710:tid 8710] [client 34.40.232.77:37712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jeannieksmith.com"] [uri "/wp-config.php.bak"] [unique_id "apZrkHunGXiQnVXdIlkwXAAAAF4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 05:44:07
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 05:19:42
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ช๐ธ
alferez
2026-09-01 05:03:10
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
VanKoh
2026-09-01 03:37:12
(1 day ago)
34.40.232.77 - - [31/Aug/2026:21:37:11 -0600] "GET /storage/logs/laravel.log HTTP/1.1" 301 162 "-" " ...
show more
34.40.232.77 - - [31/Aug/2026:21:37:11 -0600] "GET /storage/logs/laravel.log HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.40.232.77 - - [31/Aug/2026:21:37:11 -0600] "GET /.env HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.40.232.77 - - [31/Aug/2026:21:37:11 -0600] "GET /.env.prod HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Port Scan
Web App Attack
Anonymous
2026-09-01 03:07:03
(1 day ago)
34.40.232.77 - - [01/Sep/2026:03:07:02 +0000] "GET /.env.example HTTP/1.1" 404 17472 "-" "crusader-w ...
show more
34.40.232.77 - - [01/Sep/2026:03:07:02 +0000] "GET /.env.example HTTP/1.1" 404 17472 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:43:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.232.77 (77.232.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.232.77 (77.232.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:43:24.863231 2026] [security2:error] [pid 23535:tid 23535] [client 34.40.232.77:48708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wwfstudio.com"] [uri "/wp-config.php.swp"] [unique_id "apY7zAMf8ThPPLS8-AZqNQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack