๐ณ๐ฑ
ipoac.nl
2026-05-20 03:17:49
(4 months ago)
-:443 149.143.130.82 - - [20/May/2026:05:17:47 +0200] - "HEAD /root/.gitconfig HTTP/2.0" 404 1872 "- ...
show more
-:443 149.143.130.82 - - [20/May/2026:05:17:47 +0200] - "HEAD /root/.gitconfig HTTP/2.0" 404 1872 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-15 08:33:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:32:04.281806 2026] [security2:error] [pid 32121:tid 32121] [client 149.143.130.82:58455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dbrooketaylor.com"] [uri "/.env.old"] [unique_id "agbaBNbjiM7cGwjK01iJRgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:03:51
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:03:02.790501 2026] [security2:error] [pid 11084:tid 11084] [client 149.143.130.82:44443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinghydraulics.com"] [uri "/.env.live"] [unique_id "agbTNt3vHUpZ8QaPnfAmswAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:43:15
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:42:30.139345 2026] [security2:error] [pid 8617:tid 8617] [client 149.143.130.82:60837] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "callahan-co.com"] [uri "/wp-config.php.bak"] [unique_id "agbAVpR576jRaFB21H1kMgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:21:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:20:21.476115 2026] [security2:error] [pid 30135:tid 30135] [client 149.143.130.82:50475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aden.us"] [uri "/backend/.env"] [unique_id "aga7JYxmiFFC3ZjUQHvovwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 11:10:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 07:09:51.752135 2026] [security2:error] [pid 14462:tid 14462] [client 149.143.130.82:52235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "r-390.com"] [uri "/.env.production.local"] [unique_id "agMKfxfIBIO7KNj2vbVCPAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 04:52:38
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 00:52:07.918707 2026] [security2:error] [pid 4860:tid 4860] [client 149.143.130.82:39533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pizzadata.com"] [uri "/.env.local"] [unique_id "agFgd3j1sRw3TRIH53sU4AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-10 14:19:07
(4 months ago)
(caddyscan) Scanner path probe from 149.143.130.82 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.130.82 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.130.82 - - [10/May/2026:14:17:52 +0000] "HEAD /.env.backup HTTP/1.1"
[REDACTED] 200 2627 149.143.130.82 - - [10/May/2026:14:19:02 +0000] "GET /phpmyadmin/ HTTP/1.1"
[REDACTED] 200 0 149.143.130.82 - - [10/May/2026:14:19:02 +0000] "HEAD /.env.example HTTP/1.1"
[REDACTED] 200 0 149.143.130.82 - - [10/May/2026:14:19:04 +0000] "HEAD /.env.bak HTTP/1.1"
[REDACTED] 200 2627 149.143.130.82 - - [10/May/2026:14:19:04 +0000] "GET /.env.php HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 08:16:14
(4 months ago)
(caddyscan) Scanner path probe from 149.143.130.82 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.130.82 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.130.82 - - [09/May/2026:07:44:19 +0000] "HEAD /.env.backup HTTP/1.1"
[REDACTED] 200 2627 149.143.130.82 - - [09/May/2026:08:16:09 +0000] "GET /.aws/config HTTP/1.1"
[REDACTED] 200 2627 149.143.130.82 - - [09/May/2026:08:16:11 +0000] "GET /.env.json HTTP/1.1"
[REDACTED] 200 2627 149.143.130.82 - - [09/May/2026:08:16:11 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 149.143.130.82 - - [09/May/2026:08:16:13 +0000] "GET /.env.yaml HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-08 07:45:35
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 03:44:46.631638 2026] [security2:error] [pid 29347:tid 29347] [client 149.143.130.82:60965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californiarhythmproject.org"] [uri "/.env.stage"] [unique_id "af2UbvmeNOsVtEgkta2CsAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RLDD
2026-05-07 21:11:05
(4 months ago)
WP probing for vulnerabilities -ove
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-06 17:35:26
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 13:35:16.735618 2026] [security2:error] [pid 31421:tid 31450] [client 149.143.130.82:33027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adventistdeathconfusion.com"] [uri "/.git/config"] [unique_id "aft71I5yyvYBd6_5uIeXoQAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 22:55:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 18:55:49.266155 2026] [security2:error] [pid 28019:tid 28019] [client 149.143.130.82:53557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.shirleyconcrete.com"] [uri "/.env.production"] [unique_id "afkj9SSoCY1QKfs8Hsx5fwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-04 18:20:05
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.env.txt
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Safari/605.1.15
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
pocketpark
2026-05-02 14:32:00
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot