π§πͺ
cmbplf
2026-05-07 02:27:57
(4 weeks ago)
279 requests with url.path *.env
134 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
πͺπΈ
librebit
2026-04-07 00:30:31
(1 month ago)
Brute force
Brute-Force
πΊπΈ
oncord
2026-03-06 22:57:28
(2 months ago)
Form spam
Web Spam
πΊπΈ
nowyouknow
2026-03-01 04:48:01
(3 months ago)
(From [email protected] ) No experience is necessary and full training is provided. But before y ...
show more
(From [email protected] ) No experience is necessary and full training is provided. But before you apply, you need to see which role youβre best suited for.
Go here to take the Writing Job Quiz. ---> http://PaidToWrite.Online/
Once you finish the quiz, youβll get a breakdown of the best opportunities available for you right now.
Visit -----> http://PaidToWrite.Online/
show less
Phishing
Web Spam
π©πͺ
london2038.com
2026-02-11 12:15:17
(3 months ago)
Detected by WP fail2ban
2026-02-11T13:15:16.617266+01:00 wordpress: Authentication attempt from 104. ...
show more
Detected by WP fail2ban
2026-02-11T13:15:16.617266+01:00 wordpress: Authentication attempt from 104.207.45.148
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-29 09:32:18
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 04:32:13.670338 2025] [security2:error] [pid 32676:tid 32676] [client 104.207.45.148:53283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "normteslaa.com"] [uri "/.env"] [unique_id "aVJKnbvN3231-lK8PBUUlwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-29 05:41:28
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:41:23.141063 2025] [security2:error] [pid 22044:tid 22104] [client 104.207.45.148:22505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beltagin.com"] [uri "/.env"] [unique_id "aVIUgw2dUHoRkDjmH6TDQgAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Epimetheus
2025-12-29 05:06:12
(5 months ago)
Unauthorized access attempts:
From:
104.207.45.148
Method:
HTTP GET
URI Path:
/.env
UA:
"Moz ...
show more
Unauthorized access attempts:
From:
104.207.45.148
Method:
HTTP GET
URI Path:
/.env
UA:
"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-29 04:52:41
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:52:38.285726 2025] [security2:error] [pid 13103:tid 13103] [client 104.207.45.148:42397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandhage.com"] [uri "/.git/HEAD"] [unique_id "aVIJFnn2smIk_YH6A1N51gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2025-12-29 04:35:16
(5 months ago)
Accessed trap at '/.env'
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-29 04:24:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:24:20.069892 2025] [security2:error] [pid 26586:tid 26586] [client 104.207.45.148:59725] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lamariposagallery.com"] [uri "/.env"] [unique_id "aVICdG0dpP-APfkj4_dvZwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-29 03:41:59
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 22:41:52.369619 2025] [security2:error] [pid 29202:tid 29202] [client 104.207.45.148:34569] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spiralingmedia.com"] [uri "/.env"] [unique_id "aVH4gDQxEsbf1Kh1Wc3sQwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2025-12-29 03:37:24
(5 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
π΅π±
sefinek.net
2025-12-27 06:27:07
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¦πΊ
MAGIC
2025-12-19 00:04:52
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot