๐ง๐ช
sid3windr
2026-08-27 22:06:26
(9 hours ago)
GET /.env (Tarpitted for 4m20s, wasted 15.35kB)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:03:09
(9 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฎ๐ช
AutosOnShow
2026-08-27 21:36:05
(9 hours ago)
blocked for webapp attack | path requested: / | seen at 2026-08-27 21:35:21.005 |
Web App Attack
Anonymous
2026-08-27 21:21:11
(9 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐จ๐ญ
flaus
2026-08-27 20:31:41
(10 hours ago)
$f2bV_matches
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
900cm
2026-08-27 20:19:17
(10 hours ago)
[Thu Aug 27 22:19:17.169955 2026] [access_compat:error] [pid 3005238:tid 3005238] [client 136.111.8. ...
show more
[Thu Aug 27 22:19:17.169955 2026] [access_compat:error] [pid 3005238:tid 3005238] [client 136.111.8.98:32946] AH01797: client denied by server configuration: /var/www/darkintruder/.env
[Thu Aug 27 22:19:17.186574 2026] [access_compat:error] [pid 3005234:tid 3005234] [client 136.111.8.98:32956] AH01797: client denied by server configuration: /var/www/darkintruder/.env.local
[Thu Aug 27 22:19:17.187750 2026] [access_compat:error] [pid 2893340:tid 2893340] [client 136.111.8.98:32978] AH01797: client denied by server configuration: /var/www/darkintruder/.env.backup
...
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
Keith Beucler
2026-08-27 20:06:32
(11 hours ago)
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban appl ...
show more
K5 Services fail2ban jail nginx-k5-web-probes detected high-confidence web abuse. Local web ban applied. Categories: 19,21.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 19:13:04
(12 hours ago)
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /storage/logs ...
show more
Bot / scanning and/or hacking attempts: GET /env HTTP/1.1, GET /.env.bak HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.production HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /.env.example HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /.env.save HTTP/1.1, GET /wp-config.php.swp HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /actuator/env HTTP/1.1, GET /wp-config.php~ HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-08-27 19:10:17
(12 hours ago)
Web vulnerability probing: /crusader-404-probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:53:45
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:53:38.298242 2026] [security2:error] [pid 25320:tid 25320] [client 136.111.8.98:59288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mctmtrade.com"] [uri "/.env.dev"] [unique_id "apCHsgFub6jjIbSd9zkPuwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:03:15
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:03:07.977836 2026] [security2:error] [pid 17753:tid 17753] [client 136.111.8.98:41272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "book-arts.com"] [uri "/wp-config.php.bak"] [unique_id "apB7235daxDJQZSVF9EjsQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:35:19
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:35:11.496164 2026] [security2:error] [pid 29834:tid 29834] [client 136.111.8.98:54884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bnaior.org"] [uri "/.env.local"] [unique_id "apB1T1a9USEzz4yK-b8qfQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:19:27
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 136.111.8.98 (98.8.111.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:19:19.922605 2026] [security2:error] [pid 23411:tid 23427] [client 136.111.8.98:56868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chris.abney.info"] [uri "/.env.dev"] [unique_id "apBxl5diOxTpuKB2E1JTdQAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-27 16:50:50
(14 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-08-27 16:05:05
(15 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack