๐ซ๐ท
SpaceHost-Server
2026-09-21 22:23:15
(1 hour ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-20 22:21:55
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-09-20 15:17:37
(1 day ago)
34.77.109.233 - - [20/Sep/2026:23:17:36 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2050 "-" "Mozil ...
show more
34.77.109.233 - - [20/Sep/2026:23:17:36 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
34.77.109.233 - - [20/Sep/2026:23:17:36 +0800] "GET /document.php?modulepart=systemtools&file=../conf/conf.php&hashp=shared HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.77.109.233 - - [20/Sep/2026:23:17:36 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
34.77.109.233 - - [20/Sep/2026:23:17:36 +0800] "GET /static../.env HTTP/1.1" 404 7833 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.77.109.233 - - [20/Sep/2026:23:17:36 +0800] "GET /files../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 15:06:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.77.109.233 (233.109.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.109.233 (233.109.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:06:23.503168 2026] [security2:error] [pid 27206:tid 27206] [client 34.77.109.233:58348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bddev.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bddev.com"] [uri "/z9x8c7v6b5-debug-trigger-bddev.com"] [unique_id "aq_2byw863p4zYwwXdrLJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:36:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.77.109.233 (233.109.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.109.233 (233.109.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:36:49.315260 2026] [security2:error] [pid 7058:tid 7058] [client 34.77.109.233:49734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bccworldmedia.com"] [uri "/.env.local"] [unique_id "aq_vgZyC50ZWsTSBVEW1nAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:17:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.77.109.233 (233.109.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.109.233 (233.109.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:17:14.339781 2026] [security2:error] [pid 15827:tid 15827] [client 34.77.109.233:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bbproductionsonline.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bbproductionsonline.com"] [uri "/z9x8c7v6b5-debug-trigger-bbproductionsonline.com"] [unique_id "aq_q6ma3fHya4BkhHMoKUQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kbeezie
2026-09-20 14:16:39
(1 day ago)
34.77.109.233 - - [20/Sep/2026:10:16:37 -0400] "GET /index.php?s=index/\x5Cthink\x5Capp/invokefuncti ...
show more
34.77.109.233 - - [20/Sep/2026:10:16:37 -0400] "GET /index.php?s=index/\x5Cthink\x5Capp/invokefunction&function=call_user_func_array&vars[0]=file_get_contents&vars[1][]=.env HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
34.77.109.233 - - [20/Sep/2026:10:16:38 -0400] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../proc/self/environ HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
34.77.109.233 - - [20/Sep/2026:10:16:38 -0400] "GET /proc/self/cmdline HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
34.77.109.233 - - [20/Sep/2026:10:16:38 -0400] "GET /manifest.webmanifest HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
34.77.109.233 - - [20/Sep/2026:10:16:39 -0400] "GET /api/health HTTP/1.1" 429 162 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:57:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.77.109.233 (233.109.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.109.233 (233.109.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:57:48.651872 2026] [security2:error] [pid 23669:tid 23669] [client 34.77.109.233:53612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bazzoli.com"] [uri "/shop/.env"] [unique_id "aq_mXH25S1kh9jVgorjM6AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-20 13:48:57
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.77.109.233 (BE/Belgium/233.109.77.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.77.109.233 (BE/Belgium/233.109.77.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-20 13:44:30
(1 day ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
NotCool
2026-09-20 13:40:32
(1 day ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.77.109.233 (BE/Belgium/233.109.77.34.bc.googleuser ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 34.77.109.233 (BE/Belgium/233.109.77.34.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 13:33:11
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.77.109.233 (233.109.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.109.233 (233.109.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:33:07.831276 2026] [security2:error] [pid 32072:tid 32072] [client 34.77.109.233:54370] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bayfieldwis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bayfieldwis.com"] [uri "/z9x8c7v6b5-debug-trigger-bayfieldwis.com"] [unique_id "aq_gk81T6wg8VbN3IArpTwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:31:17
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-09-20 12:46:42
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:39:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.77.109.233 (233.109.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.109.233 (233.109.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:39:21.046152 2026] [security2:error] [pid 12233:tid 12233] [client 34.77.109.233:51626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batfry.com"] [uri "/.next/.env"] [unique_id "aq_T-YaixBu2K1WCSX6teAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack