๐บ๐ธ
TPI-Abuse
2026-08-29 06:29:36
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:29:32.126459 2026] [security2:error] [pid 282146:tid 282164] [client 136.107.231.130:42318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.travelusa.us"] [uri "/@fs/app/.env"] [unique_id "apJ8TANfDYkvhC1rmnqvKwAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-29 05:27:15
(1 hour ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.save
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 15_0) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15; compatible; Bytespider; +https://zhanzhang.toutiao.com/
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-08-29 04:46:14
(1 hour ago)
Attempted access to sensitive endpoint (/@fs/../.env?raw??) detected. Automated scan or unauthorized ...
show more
Attempted access to sensitive endpoint (/@fs/../.env?raw??) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:41:10
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:41:04.701967 2026] [security2:error] [pid 15224:tid 15224] [client 136.107.231.130:8568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.comicpreservation.com"] [uri "/@fs/.env"] [unique_id "apJi4BJYMHRMYm47ADVpSQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-08-29 04:11:30
(2 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐บ๐ธ
mnsf
2026-08-29 04:05:41
(2 hours ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
Anonymous
2026-08-29 03:56:09
(2 hours ago)
Scanner hitting /@fs/root/.env?raw?? on mautic.osef.cloud (GOOGL-2) โ aaguard
Brute-Force
Port Scan
๐ฉ๐ช
ger-stg-sifi1
2026-08-29 03:50:50
(2 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:38:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:38:50.966571 2026] [security2:error] [pid 14119:tid 14119] [client 136.107.231.130:49922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.suedblick.com"] [uri "/@fs/root/.env"] [unique_id "apJUSpXLf7GNJMvWb5v0GgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-29 03:05:27
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
macrob
2026-08-29 03:01:48
(3 hours ago)
2026/08/29 03:01:47 [error] 4017413#4017413: *532067129 access forbidden by rule, client: 136.107.23 ...
show more
2026/08/29 03:01:47 [error] 4017413#4017413: *532067129 access forbidden by rule, client: 136.107.231.130, server: finami.ph, request: "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0", host: "www.finami.ph"
2026/08/29 03:01:47 [error] 4017411#4017411: *532067130 access forbidden by rule, client: 136.107.231.130, server: finami.ph, request: "GET /@fs/root/.env?raw?? HTTP/2.0", host: "www.finami.ph"
2026/08/29 03:01:47 [error] 4017413#4017413: *532067129 access forbidden by rule, client: 136.107.231.130, server: finami.ph, request: "GET /@fs/.env.production?raw?? HTTP/2.0", host: "www.finami.ph"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:14:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:14:51.236651 2026] [security2:error] [pid 8792:tid 8810] [client 136.107.231.130:63418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafminstitute.com"] [uri "/@fs/.env"] [unique_id "apJAm5TCx38SkS0abLCg6wAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:47:35
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:47:30.137731 2026] [security2:error] [pid 19630:tid 19630] [client 136.107.231.130:30032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.desertedge.band"] [uri "/@fs/.env"] [unique_id "apI6Mu4bigSk57t4_0KXlQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:08:00
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.107.231.130 (130.231.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:07:53.611796 2026] [security2:error] [pid 18506:tid 18506] [client 136.107.231.130:10202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.atheismz.com"] [uri "/@fs/app/.env"] [unique_id "apIw6UEGkJM9tqJPbqB8AAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 00:39:40
(6 hours ago)
Aggressive web scan
Web App Attack