Anonymous
2026-05-20 04:07:09
(4 months ago)
(caddyscan) Scanner path probe from 149.143.135.208 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.208 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.135.208 - - [20/May/2026:04:07:08 +0000] "HEAD /wp-config.php.bak HTTP/1.1"
[REDACTED] 200 0 149.143.135.208 - - [20/May/2026:04:07:08 +0000] "HEAD /.env.bak HTTP/1.1"
[REDACTED] 200 0 149.143.135.208 - - [20/May/2026:04:07:08 +0000] "HEAD /app/.env HTTP/1.1"
[REDACTED] 200 0 149.143.135.208 - - [20/May/2026:04:07:08 +0000] "HEAD /.env.local HTTP/1.1"
[REDACTED] 200 0 149.143.135.208 - - [20/May/2026:04:07:08 +0000] "HEAD /.aws/credentials HTTP/1.1"
show less
Port Scan
๐บ๐ธ
LSPCCU
2026-05-19 04:20:07
(4 months ago)
TSEC Honeypot Network report. Threat score: 87/100. Categories: Port Scan, Hacking, Brute-Force, Web ...
show more
TSEC Honeypot Network report. Threat score: 87/100. Categories: Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: cowrie, ssh-telnet. Context: 149.
show less
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-05-15 08:24:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:23:42.511649 2026] [security2:error] [pid 18245:tid 18245] [client 149.143.135.208:38765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnhansonmemorial.org.coolingsprings.org"] [uri "/.env.docker"] [unique_id "agbYDlWbHTy1UXIwlT7nRgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 08:00:36
(4 months ago)
(caddyscan) Scanner path probe from 149.143.135.208 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.208 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.135.208 - - [13/May/2026:07:56:19 +0000] "HEAD /.git/config HTTP/1.1"
[REDACTED] 200 0 149.143.135.208 - - [13/May/2026:08:00:11 +0000] "HEAD /.env.local HTTP/1.1"
[REDACTED] 200 2627 149.143.135.208 - - [13/May/2026:08:00:24 +0000] "GET /.env.local.php HTTP/1.1"
[REDACTED] 200 2627 149.143.135.208 - - [13/May/2026:08:00:34 +0000] "GET /.env.netlify HTTP/1.1"
[REDACTED] 200 2627 149.143.135.208 - - [13/May/2026:08:00:35 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 12:33:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 08:33:35.887494 2026] [security2:error] [pid 19258:tid 19258] [client 149.143.135.208:39345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "termites.corepest.com"] [uri "/.env~"] [unique_id "agMeH-E_6LCeszP-zC5-_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-12 12:10:10
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 11:09:52
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 07:09:48.581261 2026] [security2:error] [pid 14934:tid 14934] [client 149.143.135.208:36479] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||r-390.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "r-390.com"] [uri "/wp-content/mysql.sql"] [unique_id "agMKfH7iu-2ls5bgbIy6IgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-11 13:13:01
(4 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 149.143.135.208 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 149.143.135.208 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
Anonymous
2026-05-09 11:22:02
(4 months ago)
(caddyscan) Scanner path probe from 149.143.135.208 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.208 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.135.208 - - [09/May/2026:11:14:45 +0000] "GET /phpmyadmin/index.php HTTP/1.1"
[REDACTED] 200 2627 149.143.135.208 - - [09/May/2026:11:21:59 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 149.143.135.208 - - [09/May/2026:11:21:59 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 149.143.135.208 - - [09/May/2026:11:21:59 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 149.143.135.208 - - [09/May/2026:11:21:59 +0000] "GET /.env.orig HTTP/1.1"
show less
Port Scan
๐ซ๐ฎ
as211431.net
2026-05-08 06:07:47
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (HEAD meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /app/.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 03:16:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 23:16:22.097649 2026] [security2:error] [pid 27117:tid 27154] [client 149.143.135.208:41249] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "support.reviewweaver.app"] [uri "/.env.production"] [unique_id "af1VhpY3E_bWL4WxoVN_IwAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
impra
2026-05-08 00:51:49
(5 months ago)
Detected 5 connection attempts.
Port Scan
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-05-08 00:16:26
(5 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 21:13:24
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 17:13:13.577562 2026] [security2:error] [pid 16436:tid 16436] [client 149.143.135.208:46713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clowaterart.com.aromatherapyricebags.com"] [uri "/.env.staging"] [unique_id "af0AaU-8xQiURq0bCTU1XgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-06 10:05:52
(5 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack