๐ฉ๐ช
klaus_ph
2026-09-23 10:24:32
(3 days ago)
2026-09-22 23:10:38,358 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 34.73.68.77
...
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-22 01:30:02
(4 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:45:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:45:41.761575 2026] [security2:error] [pid 5179:tid 5179] [client 34.73.68.77:43212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bastardesign.com"] [uri "/dashboard/.env"] [unique_id "arHBpQQD7VL-Q-dUqa79MgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:06:12
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:06:05.445184 2026] [security2:error] [pid 32117:tid 32180] [client 34.73.68.77:45076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bayareajazzandbluesicians.com"] [uri "/admin/.env"] [unique_id "arG4XejPE2gcsqkHyJS7bgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:48:32
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:48:24.775139 2026] [security2:error] [pid 24548:tid 24548] [client 34.73.68.77:34224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lahamradio.com"] [uri "/.env.production"] [unique_id "arG0OOZjkt9qnmuC8yJB1wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-09-21 22:41:07
(4 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 21:58:51
(4 days ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.73.68.77 - - [21/Sep/2026:23:58:51 +0200] "GET /.env.live HTTP/2.0" 404 1920 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-21 19:27:49
(4 days ago)
[21/Sep/2026:21:27:48 +0200] 179001886851.810399 34.73.68.77 35572 217.154.7.177 443
[21/Sep/2026:21 ...
show more
[21/Sep/2026:21:27:48 +0200] 179001886851.810399 34.73.68.77 35572 217.154.7.177 443
[21/Sep/2026:21:27:48 +0200] 179001886895.903684 34.73.68.77 35572 217.154.7.177 443
[21/Sep/2026:21:27:48 +0200] 179001886852.832810 34.73.68.77 35572 217.154.7.177 443
[21/Sep/2026:21:27:48 +0200] 179001886887.754939 34.73.68.77 35572 217.154.7.177 443
[21/Sep/2026:21:27:48 +0200] 179001886820.034251 34.73.68.77 35572 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:25:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:24:54.251540 2026] [security2:error] [pid 8875:tid 8875] [client 34.73.68.77:34566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.beatthegm.com"] [uri "/.env_1"] [unique_id "arGEhlReHbZp1HnSydwQUQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-21 19:22:35
(4 days ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 17:04:03
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 16:30:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.68.77 (77.68.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:30:47.641899 2026] [security2:error] [pid 8940:tid 8940] [client 34.73.68.77:41072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bassboatmagazine.com"] [uri "/static../.env"] [unique_id "arFbt2iYqLU-c5kFUagcBQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-21 14:53:04
(4 days ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 14:30:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack