๐ซ๐ท
masterguru
2026-09-13 00:33:14
(5 days ago)
Restricted File Access Attempt. Matched phrase ".ssh/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 00:31:59
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:31:54.343177 2026] [security2:error] [pid 2352404:tid 2352444] [client 34.77.168.167:40874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "merart.com"] [uri "/@fs/var/task/.env"] [unique_id "aqXu-vfSHt2m3U1MFXxW5QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-13 00:20:02
(5 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 00:11:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:11:17.780028 2026] [security2:error] [pid 30744:tid 30766] [client 34.77.168.167:43518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mentzinger.com"] [uri "/@fs/var/task/.env"] [unique_id "aqXqJeHfosvZunuXRJTFzgAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-13 00:06:30
(5 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-13 00:06 UTC
show less
Bad Web Bot
๐ณ๐ฑ
middelkoopcc
2026-09-13 00:03:01
(5 days ago)
2026-09-13 02:01:01 AH10244: invalid URI path (/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env) && 2026-09-13 02:0 ...
show more
2026-09-13 02:01:01 AH10244: invalid URI path (/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env) && 2026-09-13 02:01:01 AH10244: invalid URI path (/%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ) && 2026-09-13 02:01:01 AH10244: invalid URI path (/appearance/../../proc/self/environ) && 206 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 23:49:30
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:49:24.747890 2026] [security2:error] [pid 30585:tid 30678] [client 34.77.168.167:44018] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mensaxes.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mensaxes.net"] [uri "/rclone.conf"] [unique_id "aqXlBOUkpOFld0lYWmfjdAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-12 23:34:15
(5 days ago)
Try to access /@fs/app/.env?raw??
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 23:09:24
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:09:15.904457 2026] [security2:error] [pid 25617:tid 25617] [client 34.77.168.167:59542] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||memotronic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "memotronic.com"] [uri "/z9x8c7v6b5-debug-trigger-memotronic.com"] [unique_id "aqXbm1HXfGp1AKY8itKNOAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-12 22:55:04
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 22:33:38
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:33:34.566818 2026] [security2:error] [pid 23161:tid 23161] [client 34.77.168.167:56394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "melsjukeboxes.com"] [uri "/.env"] [unique_id "aqXTPicE2XVOLJ0wYOUXuQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-12 22:26:15
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.77.168.167 (BE/Belgium/167.168.77.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.77.168.167 (BE/Belgium/167.168.77.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ฉ๐ช
yitzhaq
2026-09-12 22:24:41
(5 days ago)
34.77.168.167 - - [13/Sep/2026:00:24:38 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 306 "-" "Mozill ...
show more
34.77.168.167 - - [13/Sep/2026:00:24:38 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 306 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
34.77.168.167 - - [13/Sep/2026:00:24:38 +0200] "GET /wp-config.php.old HTTP/2.0" 404 306 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
34.77.168.167 - - [13/Sep/2026:00:24:38 +0200] "GET /wp-config.php~ HTTP/2.0" 404 306 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
34.77.168.167 - - [13/Sep/2026:00:24:38 +0200] "GET /.env.swp HTTP/2.0" 404 306 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
34.77.168.167 - - [13/Sep/2026:00:24:38 +0200] "GET /web/.env HTTP/2.0" 404 306 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])"
34.77.168.167 - - [13/Sep/2026:00:24:38 +0200] "GET /configuration.php.bak
show less
Web App Attack
Brute-Force
๐ฉ๐ช
Melle
2026-09-12 22:17:03
(5 days ago)
Unauthorized connection attempt detected from IP address 34.77.168.167
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-12 22:15:49
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.168.167 (167.168.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:15:42.218882 2026] [security2:error] [pid 22822:tid 22822] [client 34.77.168.167:58790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||melkanbassil.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "melkanbassil.com"] [uri "/rclone.conf"] [unique_id "aqXPDubxYhKpMLdq4X_TNwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack