๐ซ๐ท
SpaceHost-Server
2026-09-21 22:23:16
(6 days ago)
Brute-Force
Web App Attack
Anonymous
2026-09-21 06:22:16
(1 week ago)
34.77.167.178 - - [20/Sep/2026:10:03:00 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 ...
show more
34.77.167.178 - - [20/Sep/2026:10:03:00 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" 34.77.167.178
34.77.167.178 - - [20/Sep/2026:10:03:00 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 34.77.167.178
34.77.167.178 - - [20/Sep/2026:10:03:00 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 34.77.167.178
34.77.167.178 - - [20/Sep/2026:10:03:00 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" 34.77.167.178
34.77.167.178 - - [20/Sep/2026:10:03:00 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 34.77.167.178
3
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-20 22:21:56
(1 week ago)
Brute-Force
Web App Attack
๐ฌ๐ง
bensmithurst
2026-09-20 15:31:45
(1 week ago)
34.77.167.178 - - [20/Sep/2026:15:31:45 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1 ...
show more
34.77.167.178 - - [20/Sep/2026:15:31:45 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
34.77.167.178 - - [20/Sep/2026:15:31:45 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
34.77.167.178 - - [20/Sep/2026:15:31:45 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
34.77.167.178 - - [20/Sep/2026:15:31:45 +0000] "GET /..%2f.env HTTP/1.1" 400 150 "-" "-"
34.77.167.178 - - [20/Sep/2026:15:31:45 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:14:02
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.77.167.178 (178.167.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.167.178 (178.167.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:13:59.594977 2026] [security2:error] [pid 14191:tid 14191] [client 34.77.167.178:58486] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||benjaminshaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "benjaminshaw.com"] [uri "/z9x8c7v6b5-debug-trigger-benjaminshaw.com"] [unique_id "aq_4Nw3cp8FN12SY58O_wQAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:50:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:50:44.187126 2026] [security2:error] [pid 31107:tid 31107] [client 34.77.167.178:48236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "benefit-design.com"] [uri "/.env.bak"] [unique_id "aq_yxJuGyj0IG8x3-EsdJgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:32:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:32:36.973064 2026] [security2:error] [pid 17652:tid 17652] [client 34.77.167.178:34896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bencramerinc.com"] [uri "/admin/.env"] [unique_id "aq_uhNW7AolhAJjRXTxRaAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-20 14:15:18
(1 week ago)
(mod_security) mod_security (id:930130) triggered by 34.77.167.178 (BE/Belgium/178.167.77.34.bc.goog ...
show more
(mod_security) mod_security (id:930130) triggered by 34.77.167.178 (BE/Belgium/178.167.77.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 13:48:18
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 13:39:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:39:27.017898 2026] [security2:error] [pid 16363:tid 16432] [client 34.77.167.178:44044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beltagin.com"] [uri "/css../.env"] [unique_id "aq_iDwhP2Ec8aTqJGSvQFAAAAg0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-09-20 13:33:44
(1 week ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /ssl/localhost.key [RATE LIMITED - 1800s quarantine] | P ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /ssl/localhost.key [RATE LIMITED - 1800s quarantine] | Pays: BE | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplex
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 13:30:19
(1 week ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.77.167.178 - - [20/Sep/2026:15:30:05 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:18:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.167.178 (178.167.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:18:32.056325 2026] [security2:error] [pid 14211:tid 14211] [client 34.77.167.178:53284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bellehollow.com"] [uri "/userfiles"] [unique_id "aq_dKKe2ytuPxd-XP2LPHwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-20 13:14:12
(1 week ago)
Blocked by ConnMonitor: Bad Bot
Bad Web Bot
Spoofing
๐บ๐ธ
TPI-Abuse
2026-09-20 12:58:36
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.77.167.178 (178.167.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.167.178 (178.167.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:58:29.942002 2026] [security2:error] [pid 30073:tid 30073] [client 34.77.167.178:54144] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||belintxon.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "belintxon.com"] [uri "/privatekey.key"] [unique_id "aq_YdQyH1bAVMTR9E5QKVgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack