๐ซ๐ฎ
as211431.net
2026-04-05 12:42:02
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-09 21:40:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:40:02.841713 2026] [security2:error] [pid 21840:tid 21840] [client 104.207.52.242:26649] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garrisonfinancial.net"] [uri "/.env.staging"] [unique_id "aYpUMsVsz6eP8uCCzCc34AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 19:30:03
(4 months ago)
Blocking for trying to access an exploit file: /backend/.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 16:28:26
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 11:28:19.203048 2026] [security2:error] [pid 1172346:tid 1172346] [client 104.207.52.242:53331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftiptondds.com"] [uri "/v2/.git/config"] [unique_id "aYoLI3AgCXW9eHo1yn5jLgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 08:27:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 03:27:03.674187 2026] [security2:error] [pid 14818:tid 14818] [client 104.207.52.242:23077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fydelitybags.com"] [uri "/.env.staging"] [unique_id "aYmaV-FJpPrDMyHVtAcobQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HERA - Operations
2026-01-06 21:46:47
(5 months ago)
sensobox - searching for vulnerable scripts: .env 2026/01/06 22:46:47
Web App Attack
Anonymous
2025-12-30 13:20:55
(5 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:31:29
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:31:25.633716 2025] [security2:error] [pid 2799:tid 2799] [client 104.207.52.242:39223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3-6trucking.com"] [uri "/.env"] [unique_id "aVISLUQf4VXeJoO_KZoJ3gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:57:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:57:10.950962 2025] [security2:error] [pid 24475:tid 24475] [client 104.207.52.242:45327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siczewicz.com"] [uri "/.env"] [unique_id "aVIKJpvNzcVFH4qKvic_HAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 04:10:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 23:10:25.215094 2025] [security2:error] [pid 30015:tid 30015] [client 104.207.52.242:20295] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schmeagle.com"] [uri "/.svn/wc.db"] [unique_id "aVH_McZHf57zHnXl0Ig0zwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:34:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:29:23.698846 2025] [security2:error] [pid 9707:tid 9889] [client 104.207.52.242:54231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.flipkimmel.com"] [uri "/.env"] [unique_id "aSQlc_BpxIwoZY4UysC2EwAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:53:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:53:12.965029 2025] [security2:error] [pid 9084:tid 9084] [client 104.207.52.242:43119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.southsideaccountingservices.com"] [uri "/.git/HEAD"] [unique_id "aSQA2NZWo9HOEQUsVqpwTwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:05:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.52.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:05:28.871121 2025] [security2:error] [pid 22554:tid 22554] [client 104.207.52.242:46875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.meridianranchdrc.org"] [uri "/.git/HEAD"] [unique_id "aSPnmA_Cbbty9SBxhcQVJAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-10-13 01:12:36
(7 months ago)
Form spam
Web Spam
Anonymous
2025-10-11 03:45:50
(7 months ago)
Attempted brute force login to web vpn 72 time(s); last attempt for 2025.10.11 is noted in report ti ...
show more
Attempted brute force login to web vpn 72 time(s); last attempt for 2025.10.11 is noted in report timestamp
show less
Hacking
Brute-Force