🇺🇸
TPI-Abuse
2026-09-06 13:07:24
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:07:17.929018 2026] [security2:error] [pid 11968:tid 11968] [client 147.90.209.187:28273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "delicatessefoods.com"] [uri "/.env"] [unique_id "ap1lhfHw809vbJld1nrpAwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 10:17:57
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:17:49.669917 2026] [security2:error] [pid 21382:tid 21382] [client 147.90.209.187:42807] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "financesf.com"] [uri "/.env"] [unique_id "ap09za9InutXPiwN-u0lBQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:42:44
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:42:36.492313 2026] [security2:error] [pid 13427:tid 13427] [client 147.90.209.187:44661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kurtkaufman.com"] [uri "/.env"] [unique_id "ap01jJhMEzhuuYeBrCwA4wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:27:51
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:27:44.335543 2026] [security2:error] [pid 27069:tid 27083] [client 147.90.209.187:50729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markhoran.pictures"] [uri "/.env"] [unique_id "apz50B9X2ldeAERJNGsv3QAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:23:47
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:23:40.655133 2026] [security2:error] [pid 17219:tid 17219] [client 147.90.209.187:58603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swurgentvet.com"] [uri "/.env"] [unique_id "apzAnByRHyLlIO1bHsBW-AAAAH0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:18:08
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 147.90.209.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:18:01.649244 2026] [security2:error] [pid 11729:tid 11761] [client 147.90.209.187:44627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mwcecommerce.com"] [uri "/.env"] [unique_id "apyxOSdCOveZ2ZzsmBkrAwAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-08-30 06:01:41
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 212238 (Datacamp Limited ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 212238 (Datacamp Limited)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-08-30T04:58:12Z
Ray ID: a33138126dfa9970
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
show less
Bad Web Bot
🇮🇹
Progetto1
2026-08-30 02:15:03
(1 week ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
slay3r9903
2026-08-29 20:58:03
(1 week ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
🇺🇸
Charlesiv
2026-08-29 16:00:21
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 212238 (Datacamp Limited ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 212238 (Datacamp Limited)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-08-29T15:27:53Z
Ray ID: a32c95165ad135fc
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.1
show less
Bad Web Bot
🇵🇱
sefinek.net
2026-08-29 15:25:48
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇬🇧
consul.to
2026-08-29 09:16:24
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
🇨🇦
dispensight
2026-08-29 00:00:00
(1 week ago)
[SecureLeaf/Dispensight] Host beaconing to sinkholed Omegatech C2 domain gettrumpmemestrendingtokens ...
show more
[SecureLeaf/Dispensight] Host beaconing to sinkholed Omegatech C2 domain gettrumpmemestrendingtokens.com (SL-2026-004 / SL-ADV-2026-WP-001). 1 request(s) to sinkhole endpoint /sink.html with Referer http://gettrumpmemestrendingtokens.com/. Consistent with EtherHiding/ClickFix campaign beacon activity. Source: secureleaf.dispensight.com SSL log 2026-08-29.
show less
Bad Web Bot
Exploited Host
🇩🇪
LRob
2026-08-18 05:41:34
(2 weeks ago)
Credential and secrets file probing | req: /.git/config | UA: Go-http-client/1.1
Hacking
Web App Attack
Anonymous
2026-08-15 16:31:57
(3 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host