🇧🇾
lns.bz
2026-08-30 02:00:39
(7 hours ago)
Too many 404 requests [BY]
Web App Attack
🇫🇮
mnazibo
2026-08-30 02:00:05
(7 hours ago)
Date: 30/Aug/2026 04:50:24 | Reported IP: 104.196.167.33 mod_security | id: 930130 | US/group.my_dom ...
show more
Date: 30/Aug/2026 04:50:24 | Reported IP: 104.196.167.33 mod_security | id: 930130 | US/group.my_domain/- | Connections: 18 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /%2eenv; /.env; /.env.; /.env/; //.env; /.ENV; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.prod; /.env.production; /.env.save; /wp-config.php~; /wp-config.php.bak; /wp-config.php.swp | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
🇿🇦
conure.sh
2026-08-29 12:01:53
(21 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇨🇭
Ribeye375
2026-08-29 03:19:43
(1 day ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 03:01:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:01:02.777323 2026] [security2:error] [pid 29418:tid 29418] [client 104.196.167.33:49000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kooroshvaziri.com"] [uri "/.env.prod"] [unique_id "apJLbpr0OwSXc9oXGbpBigAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Lino Project
2026-08-29 02:51:34
(1 day ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
🇺🇸
TPI-Abuse
2026-08-29 01:49:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:49:06.531793 2026] [security2:error] [pid 31357:tid 31357] [client 104.196.167.33:50116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.alphacom.us"] [uri "/.env.local"] [unique_id "apI6ksCZ8-PQP7ntHMbJXwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-08-29 01:40:24
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.swp
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
FD-IX
2026-08-29 00:50:27
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-08-28 23:49:32
(1 day ago)
104.196.167.33 - - [29/Aug/2026:01:49:31 +0200] "GET /.env.save HTTP/1.1" 403 5613 "-" "crusader-wor ...
show more
104.196.167.33 - - [29/Aug/2026:01:49:31 +0200] "GET /.env.save HTTP/1.1" 403 5613 "-" "crusader-worker/1.0"
104.196.167.33 - - [29/Aug/2026:01:49:31 +0200] "GET /.env.backup HTTP/1.1" 403 5613 "-" "crusader-worker/1.0"
104.196.167.33 - - [29/Aug/2026:01:49:31 +0200] "GET /.env.bak HTTP/1.1" 403 5613 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:45:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:45:06.242232 2026] [security2:error] [pid 20180:tid 20180] [client 104.196.167.33:55840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orthopaedicsurgical.com"] [uri "/wp-config.php~"] [unique_id "apIdgv9FpywwexH5TPNBOAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
Lunix
2026-08-28 23:10:52
(1 day ago)
Brute-Force
Web App Attack
🇩🇪
webanyone
2026-08-28 22:47:19
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:09:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.167.33 (33.167.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:09:51.405343 2026] [security2:error] [pid 31887:tid 31887] [client 104.196.167.33:54758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allisonokon.com"] [uri "/.env.local"] [unique_id "apIHL_l6BKb0pghp5yfKFwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 22:03:40
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking