๐บ๐ธ
TPI-Abuse
2026-09-21 05:56:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:56:52.633558 2026] [security2:error] [pid 30892:tid 30892] [client 34.77.36.78:45892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alhill.com"] [uri "/css../.env"] [unique_id "arDHJN8gSVwnUZzNRxx2bQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-21 04:27:57
(2 hours ago)
Malicious activity from IP detected: crowdsecurity/http-path-traversal-probing.
Web App Attack
Hacking
๐บ๐ธ
WizardsToolkit
2026-09-21 04:26:40
(2 hours ago)
tried to access forbidden files; attempted to access /app/.env
Web App Attack
๐บ๐ธ
TAY
2026-09-21 03:28:46
(3 hours ago)
34.77.36.78 - - [21/Sep/2026:11:28:45 +0800] "GET /@fs/../.env?import&raw?? HTTP/1.1" 404 363 "-" "M ...
show more
34.77.36.78 - - [21/Sep/2026:11:28:45 +0800] "GET /@fs/../.env?import&raw?? HTTP/1.1" 404 363 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
34.77.36.78 - - [21/Sep/2026:11:28:46 +0800] "GET /public../.env HTTP/1.1" 404 363 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
34.77.36.78 - - [21/Sep/2026:11:28:46 +0800] "GET /dist../.env HTTP/1.1" 404 363 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
34.77.36.78 - - [21/Sep/2026:11:28:46 +0800] "GET /js../.env HTTP/1.1" 404 363 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
34.77.36.78 - - [21/Sep/2026:11:28:46 +0800] "GET /build../.env HTTP/1.1" 404 363 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.77.36.78 - - [21/Sep/2026:11:28:46 +0800] "GET /userfiles?path=../../../.env HTTP/1.1" 404 363 "-" "Mozill
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 03:26:55
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:26:51.298475 2026] [security2:error] [pid 19441:tid 19441] [client 34.77.36.78:48640] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aguasolar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aguasolar.com"] [uri "/z9x8c7v6b5-debug-trigger-aguasolar.com"] [unique_id "arCj-yKnqRLwkAdZ0zZdAgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 03:03:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:03:40.786873 2026] [security2:error] [pid 24758:tid 24758] [client 34.77.36.78:43492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ajdejano.janbloom-art.com"] [uri "/.env.production"] [unique_id "arCejOlLxRwckRf1ZO0IGQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SiyCah
2026-09-21 03:00:02
(4 hours ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 02:54:41
(4 hours ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:21:01
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:20:55.879654 2026] [security2:error] [pid 26348:tid 26348] [client 34.77.36.78:47658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.airlinechristmascards.com"] [uri "/.git/HEAD"] [unique_id "arBqVxqI9naCD8GI5aF4vwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-20 22:58:08
(8 hours ago)
Bad bot identified by user agent
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 22:19:23
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:19:18.345966 2026] [security2:error] [pid 11366:tid 11461] [client 34.77.36.78:49446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.ajbruner.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.ajbruner.com"] [uri "/ssl/localhost.key"] [unique_id "arBb5hnaBE6kEOuHqfsb0QAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Quarks Solutions
2026-09-20 22:18:06
(8 hours ago)
crowdsecurity/appsec-vpatch
Web App Attack
Anonymous
2026-09-20 22:14:14
(8 hours ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-20 21:54:28
(9 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:38:24
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.77.36.78 (78.36.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:38:19.305157 2026] [security2:error] [pid 15225:tid 15315] [client 34.77.36.78:59998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.credit-card-cap.com|F|2"] [data ".credit-card-cap.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.credit-card-cap.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.credit-card-cap.com"] [unique_id "arBSS_ZUUJrkeyvZFd3s_AAAAdg"]
show less
Brute-Force
Bad Web Bot
Web App Attack