๐ฉ๐ช
Trueforce Threat Report
2026-05-20 22:21:16
(3 months ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
Anonymous
2026-05-16 21:18:28
(3 months ago)
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.134.63 - - [16/May/2026:21:18:23 +0000] "HEAD /.env.local HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [16/May/2026:21:18:26 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [16/May/2026:21:18:27 +0000] "HEAD /.aws/credentials HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [16/May/2026:21:18:27 +0000] "HEAD /.git/config HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [16/May/2026:21:18:27 +0000] "HEAD /root/.aws/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-16 07:57:46
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 03:57:32.652024 2026] [security2:error] [pid 24929:tid 24929] [client 149.143.134.63:33167] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.boat-registration-france.com.boatregistrationdelaware.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.boat-registration-france.com.boatregistrationdelaware.com"] [uri "/dump.sql"] [unique_id "aggjbDDlqTfpu-0EXVhqqAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:59:51
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:59:17.273922 2026] [security2:error] [pid 12206:tid 12206] [client 149.143.134.63:51593] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||spores101.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "spores101.com"] [uri "/config/master.key"] [unique_id "agbgZepyqjUPEqIcZzl6IQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:42:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:42:24.310793 2026] [security2:error] [pid 20655:tid 20667] [client 149.143.134.63:58381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.getfullyconnected.com.richardleeweatherman.com"] [uri "/.env.qa"] [unique_id "agbccAS8NqowuojCS1O_2QAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:26:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:25:35.405853 2026] [security2:error] [pid 24269:tid 24269] [client 149.143.134.63:54071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wilsonclassof81.org"] [uri "/.env.release"] [unique_id "agbYf9CDWafaqotVQqtAfgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:00:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:00:26.865851 2026] [security2:error] [pid 25890:tid 25890] [client 149.143.134.63:38333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.scc1.us"] [uri "/api/.env"] [unique_id "agbSmlmn2wxaQRjxO-qhrwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:32:22
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:31:36.255264 2026] [security2:error] [pid 31372:tid 31372] [client 149.143.134.63:44707] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boens.org"] [uri "/.env.dev"] [unique_id "agbL2Lg0jjHlx1iB2ph0fwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 08:07:47
(3 months ago)
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.134.63 - - [13/May/2026:08:00:25 +0000] "GET /phpMyAdmin/ HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [13/May/2026:08:07:44 +0000] "HEAD /.env.dist HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [13/May/2026:08:07:44 +0000] "GET /.DS_Store HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [13/May/2026:08:07:44 +0000] "HEAD /.env.old HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [13/May/2026:08:07:44 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-11 04:32:12
(3 months ago)
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.134.63 - - [11/May/2026:04:32:06 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [11/May/2026:04:32:06 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [11/May/2026:04:32:06 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [11/May/2026:04:32:06 +0000] "HEAD /.git/config HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [11/May/2026:04:32:06 +0000] "GET /.env.secret HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-10 14:18:17
(3 months ago)
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.134.63 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.134.63 - - [10/May/2026:13:55:57 +0000] "HEAD /.env~ HTTP/1.1"
[REDACTED] 200 0 149.143.134.63 - - [10/May/2026:13:56:00 +0000] "HEAD /app/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [10/May/2026:14:17:50 +0000] "GET /api/actuator/env HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [10/May/2026:14:18:13 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 149.143.134.63 - - [10/May/2026:14:18:13 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐ซ๐ฎ
as211431.net
2026-05-08 06:08:02
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.env.live
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-05-08 04:00:53
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communications LLC)
Protocol: HTTP/2 (HEAD method)
Endpoint: /.env.development
Timestamp: 2026-05-08T02:56:07Z
Ray ID: 9f853081ac350576
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-07 21:55:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.134.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 17:55:02.397839 2026] [security2:error] [pid 18153:tid 18163] [client 149.143.134.63:53075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "montanatribes.org"] [uri "/.env.production"] [unique_id "af0KNlTXOrg6W_urt8Y_2wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-07 00:13:16
(3 months ago)
Web attack/malicious scanning detected
Web App Attack