๐บ๐ธ
TPI-Abuse
2026-09-13 10:06:10
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:06:04.366646 2026] [security2:error] [pid 1651:tid 1651] [client 34.77.168.167:60040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chicagochristmascards.com"] [uri "/static../.env"] [unique_id "aqZ1jLdcuLJpr40ecRlcuwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
mypatricks
2026-09-13 10:02:27
(3 weeks ago)
34.77.168.167 | Port: 12034 | DNS: 167.168.77.34.bc.googleusercontent.com 2026-09-13T18:02:25+08:00 ...
show more
34.77.168.167 | Port: 12034 | DNS: 167.168.77.34.bc.googleusercontent.com 2026-09-13T18:02:25+08:00 Europe/Brussels | Fake Applebot Detected | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1) HTTP/1.1 443 GET | URL: /api/v2/settings | Ref: - | Country: BE/Belgium/+01:00 IP City: Brussels a3a650f76aa8d12e-CDG/Paris, France 5 hits/2 secs Robots 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-13 09:35:53
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:35:49.553923 2026] [security2:error] [pid 6145:tid 6145] [client 34.77.168.167:53594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cherryblossomplayers.com"] [uri "/@fs/.env"] [unique_id "aqZudQc2MkSDJ5peMyfFtgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mc4bbs
2026-09-13 08:35:54
(3 weeks ago)
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show more
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /@fs/.env?import&?raw?? -> 404 UA=""; GET /wp-json -> 404 UA=""; GET /@fs/.env?raw&url?? -> 404 UA=""; GET /@fs/.env?url&raw?? -> 404 UA=""; GET /__vite_rsc_findSourceMapURL?filename=file:///app/.env&environmentName=rsc -> 404 UA=""
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-13 08:18:15
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:18:08.124034 2026] [security2:error] [pid 22619:tid 22619] [client 34.77.168.167:48358] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chateau-saleza-bruges.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chateau-saleza-bruges.com"] [uri "/rclone.conf"] [unique_id "aqZcQKN26zrEFfaBP7yA_gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-13 06:00:01
(3 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
Major Hostility
2026-09-13 02:33:36
(3 weeks ago)
"GET /dist/manifest.json HTTP/1.1" 404
"GET /webpack-stats.json HTTP/1.1" 404
"GET /proc/self/cgroup ...
show more
"GET /dist/manifest.json HTTP/1.1" 404
"GET /webpack-stats.json HTTP/1.1" 404
"GET /proc/self/cgroup HTTP/1.1" 404
"GET /signin HTTP/1.1" 404
"GET /sign-in HTTP/1.1" 404
"GET /auth HTTP/1.1" 404
"GET /auth/login HTTP/1.1" 404
"GET /account/login HTTP/1.1" 404
"GET /assets/manifest.json HTTP/1.1" 404
"GET /users/login HTTP/1.1" 404
"GET /register HTTP/1.1" 404
"GET /user/login HTTP/1.1" 404
"GET /forgot-password HTTP/1.1" 404
"GET /reset-password HTTP/1.1" 404
"GET /admin HTTP/1.1" 404
"GET /admin/login HTTP/1.1" 404
"GET /dashboard HTTP/1.1" 404
"GET /console HTTP/1.1" 404
"GET /manifest.json HTTP/1.1" 404
"GET /asset-manifest.json HTTP/1.1" 404
"GET%2
show less
Web App Attack
๐ฆ๐บ
Block Rockin' Beats
2026-09-13 02:28:04
(3 weeks ago)
Scanning for exploitable scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 02:14:54
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 22:14:49.838941 2026] [security2:error] [pid 20658:tid 20658] [client 34.77.168.167:36278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "messengersforchrist.com"] [uri "/@fs/var/task/.env"] [unique_id "aqYHGdliyKJgg5-HN-MS9wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-13 02:12:57
(3 weeks ago)
Aggressive web search of vulnerable pages: /docker-compose.yml /userfiles?path=../../.env /userfiles ...
show more
Aggressive web search of vulnerable pages: /docker-compose.yml /userfiles?path=../../.env /userfiles?path=../../../.env /userfiles?path=../../. ...
show less
Web App Attack
๐ซ๐ท
LRob
2026-09-13 02:07:25
(3 weeks ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /@fs/home/ubuntu/.aws/credentials | 2026-09-13 02:07 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
antlac1
2026-09-13 01:51:31
(3 weeks ago)
crowdsecurity/http-bad-user-agent
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 01:33:27
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:33:22.556104 2026] [security2:error] [pid 15663:tid 15663] [client 34.77.168.167:56420] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||merlinaerospace.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "merlinaerospace.com"] [uri "/z9x8c7v6b5-debug-trigger-merlinaerospace.com"] [unique_id "aqX9Yndqw4eAdBaFjIUO_wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-13 01:02:48
(3 weeks ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ฎ
netman
2026-09-13 00:47:16
(3 weeks ago)
HTTP: 34.77.168.167 blocked because of 500 failures
...
Port Scan
Web App Attack