๐บ๐ธ
TPI-Abuse
2026-05-20 20:22:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 16:22:36.593132 2026] [security2:error] [pid 6415:tid 6415] [client 149.143.128.192:33395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tuscarora-international.com.uniquelaos.com"] [uri "/.env"] [unique_id "ag4YDEe_LWpPoi0uvgZ4ggAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-19 05:04:45
(4 months ago)
(caddyscan) Scanner path probe from 149.143.128.192 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.128.192 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.128.192 - - [19/May/2026:05:04:43 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [19/May/2026:05:04:43 +0000] "HEAD /app/.env HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [19/May/2026:05:04:44 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [19/May/2026:05:04:44 +0000] "HEAD /.env.backup HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [19/May/2026:05:04:44 +0000] "HEAD /.aws/credentials HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-18 07:54:38
(4 months ago)
(caddyscan) Scanner path probe from 149.143.128.192 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.128.192 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.128.192 - - [18/May/2026:07:54:32 +0000] "HEAD /root/.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [18/May/2026:07:54:32 +0000] "HEAD /root/.aws/credentials HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [18/May/2026:07:54:32 +0000] "HEAD /.aws/credentials HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [18/May/2026:07:54:32 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.128.192 - - [18/May/2026:07:54:32 +0000] "HEAD /.env~ HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-16 11:45:08
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 07:44:58.076599 2026] [security2:error] [pid 12457:tid 12457] [client 149.143.128.192:40495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kemblebros.kemblebrothers.com"] [uri "/.env.bak"] [unique_id "aghYuouVlDAlZQqjmJT9mwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:33:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:32:46.423495 2026] [security2:error] [pid 31825:tid 31825] [client 149.143.128.192:54373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "movierebuspuzzles.com"] [uri "/.env.development.local"] [unique_id "agbaLufKGLK7YtpKlLL10wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:16:38
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:16:05.338532 2026] [security2:error] [pid 23405:tid 23405] [client 149.143.128.192:44573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazingwelding.com"] [uri "/.env.backup"] [unique_id "agbWRcZ0jx4PvLBfEqzF7QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:36:46
(4 months ago)
(mod_security) mod_security (id:949110) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:36:23.138868 2026] [security2:error] [pid 16128:tid 16128] [client 149.143.128.192:56941] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mijn.photo"] [uri "/.env.vault"] [unique_id "agbM9-CHVdhVIL2rZzuA6QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:05:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:04:48.708091 2026] [security2:error] [pid 2858:tid 2858] [client 149.143.128.192:59577] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galvez.cc"] [uri "/wp-config.php.bak"] [unique_id "agbFkHWmiKQxtiPZNcWtOQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:42:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:41:17.482874 2026] [security2:error] [pid 23213:tid 23213] [client 149.143.128.192:53755] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gods-law.com"] [uri "/.env.test"] [unique_id "agbADXhmSEVVjzeVCK8KxwAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 10:55:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 06:54:58.268489 2026] [security2:error] [pid 16133:tid 16133] [client 149.143.128.192:60933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baird.net"] [uri "/.hg/store"] [unique_id "agMHAnAd6qNWQF29WHzkgQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 18:13:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 14:12:41.358890 2026] [security2:error] [pid 26100:tid 26100] [client 149.143.128.192:47831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jamelrobinson.com"] [uri "/.env.dev"] [unique_id "agDKmVntlNBW1y_ubehhaAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 23:35:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 19:34:59.833735 2026] [security2:error] [pid 5436:tid 5567] [client 149.143.128.192:43397] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ennerdale.org"] [uri "/.env.uat"] [unique_id "af5zIwg5Cy_lF5ZP4FC-dQAAAos"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 19:21:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 15:20:50.713218 2026] [security2:error] [pid 17492:tid 17492] [client 149.143.128.192:60385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ficklepassionproductions.com"] [uri "/.env.production"] [unique_id "af43kjeHorXcv45on0f8HwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-08 06:07:59
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (HEAD method ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (HEAD method)
Endpoint: /wp-content/mysql.sql
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-05-08 04:00:49
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communications LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /.env.development
Timestamp: 2026-05-08T02:56:09Z
Ray ID: 9f85308de80fc5e9
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
show less
Bad Web Bot