๐บ๐ธ
TPI-Abuse
2026-05-23 22:41:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 18:41:20.978154 2026] [security2:error] [pid 27152:tid 27218] [client 149.143.130.84:38591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gqsi.aafm.us"] [uri "/.env.ci"] [unique_id "ahItEBDdjvxO1kw6QkmkkgAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:39:32
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:39:24.120042 2026] [security2:error] [pid 32249:tid 32249] [client 149.143.130.84:39585] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lifeinsmoke.yeejia.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lifeinsmoke.yeejia.net"] [uri "/db.sql"] [unique_id "agbbvFPEbGVEumVON1J0IgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:32:06
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:31:34.436866 2026] [security2:error] [pid 24220:tid 24220] [client 149.143.130.84:39241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sympalais.com"] [uri "/.env.orig"] [unique_id "agbL1vb4LCTGQ-BPpbxxXwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 09:16:35
(4 months ago)
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.130.84 - - [13/May/2026:08:16:53 +0000] "HEAD /.env.php HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [13/May/2026:08:16:54 +0000] "GET /.aws/config HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [13/May/2026:08:36:29 +0000] "GET /api/actuator/configprops HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [13/May/2026:08:48:50 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [13/May/2026:09:16:32 +0000] "GET /.DS_Store HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-05-12 12:10:09
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
Anonymous
2026-05-10 12:34:19
(4 months ago)
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.130.84 - - [10/May/2026:12:34:13 +0000] "HEAD /root/.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.130.84 - - [10/May/2026:12:34:14 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [10/May/2026:12:34:14 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [10/May/2026:12:34:14 +0000] "GET /.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.130.84 - - [10/May/2026:12:34:15 +0000] "HEAD /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 14:47:55
(5 months ago)
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.130.84 - - [09/May/2026:14:18:36 +0000] "GET /.env.development.local HTTP/1.1"
[REDACTED] 200 0 149.143.130.84 - - [09/May/2026:14:43:48 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [09/May/2026:14:47:49 +0000] "GET /.env.2 HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [09/May/2026:14:47:51 +0000] "GET /.env.k8s HTTP/1.1"
[REDACTED] 200 2627 149.143.130.84 - - [09/May/2026:14:47:52 +0000] "GET /.env.template HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 06:20:02
(5 months ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-05-09 02:52:00
(5 months ago)
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.130.84 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 9075432www.wildcardprobe-1777098499974961099.bicities.org 200 0 149.143.130.84 - - [09/May/2026:02:34:17 +0000] "HEAD /.aws/credentials HTTP/1.1"
9075432www.wildcardprobe-1777098499974961099.bicities.org 200 2627 149.143.130.84 - - [09/May/2026:02:34:18 +0000] "GET /admin/.DS_Store HTTP/1.1"
9075432www.wildcardprobe-1777098499974961099.bicities.org 200 2627 149.143.130.84 - - [09/May/2026:02:34:19 +0000] "GET /.env.local HTTP/1.1"
9075432www.wildcardprobe-1777098499974961099.bicities.org 200 0 149.143.130.84 - - [09/May/2026:02:34:21 +0000] "HEAD /.git/config HTTP/1.1"
7705321432wildcardprobe-1777274331506357801.bicities.org 200 2627 149.143.130.84 - - [09/May/2026:02:51:57 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-08 19:21:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 15:20:49.972254 2026] [security2:error] [pid 26335:tid 26335] [client 149.143.130.84:39085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ficklepassionproductions.com"] [uri "/.git/config"] [unique_id "af43kZVtAPxrgOvNnKAj3AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-08 18:38:21
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.env.testing
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-05-08 10:06:45
(5 months ago)
Scanning/Probing (22)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-06 19:38:36
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.130.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 15:38:31.316251 2026] [security2:error] [pid 21584:tid 21584] [client 149.143.130.84:40157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.futurbike.it"] [uri "/.git/objects/"] [unique_id "afuYt-YTaqHLvTfzMYTzyQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RLDD
2026-05-05 19:36:23
(5 months ago)
WP probing for vulnerabilities -nov
Web App Attack
๐บ๐ธ
nyt
2026-05-05 09:39:35
(5 months ago)
Sensitive File Probe, Request for backup.sql file is unusual
SQL Injection
Web App Attack