Anonymous
2026-05-20 20:53:05
(3 months ago)
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.135.225 - - [20/May/2026:20:53:04 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [20/May/2026:20:53:04 +0000] "GET /wp-config.php.save HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [20/May/2026:20:53:04 +0000] "GET /wp-config.php~ HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [20/May/2026:20:53:04 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [20/May/2026:20:53:04 +0000] "GET /wp-config.php.old HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-19 17:14:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 13:14:07.749046 2026] [security2:error] [pid 17221:tid 17221] [client 149.143.135.225:51467] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ratbird.com"] [uri "/.env.gcp"] [unique_id "agyaXzEZWp6sWsCK5JTcOQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 13:11:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.135.225 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.135.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:11:03.920660 2026] [security2:error] [pid 9034:tid 9053] [client 149.143.135.225:53841] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tributetomarilyn.com"] [uri "/.env.demo"] [unique_id "agm-Z3bL0dqOIL_xmf0_VQAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 08:49:06
(3 months ago)
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.135.225 - - [13/May/2026:08:00:15 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.135.225 - - [13/May/2026:08:00:15 +0000] "HEAD /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [13/May/2026:08:16:36 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [13/May/2026:08:48:47 +0000] "GET /api/actuator/configprops HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [13/May/2026:08:49:04 +0000] "GET /.env.bak HTTP/1.1"
show less
Port Scan
๐ซ๐ท
masterguru
2026-05-11 13:13:02
(3 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 149.143.135.225 (US/United States/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 149.143.135.225 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
dwmp
2026-05-11 10:01:28
(3 months ago)
Url probing: /.env.staging
Web App Attack
Anonymous
2026-05-10 05:33:10
(3 months ago)
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:05:15:57 +0000] "GET /.env.prod HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:05:15:59 +0000] "GET /.env.1 HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:05:16:01 +0000] "GET /.env-old HTTP/1.1"
[REDACTED] 200 0 149.143.135.225 - - [10/May/2026:05:33:05 +0000] "HEAD /root/.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.135.225 - - [10/May/2026:05:33:05 +0000] "HEAD /.aws/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-10 02:24:38
(3 months ago)
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.135.225 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:01:40:46 +0000] "GET /.env.orig HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:01:40:47 +0000] "GET /.env.uat HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:01:40:47 +0000] "GET /.env.ci HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:01:40:48 +0000] "GET /.env.staging HTTP/1.1"
[REDACTED] 200 2627 149.143.135.225 - - [10/May/2026:02:24:37 +0000] "GET /.env.bak HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
Ba-Yu
2026-05-08 16:22:14
(3 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
theanalogmaker
2026-05-07 02:30:04
(4 months ago)
CrowdSec: AbuseIPDB 90% (US, 34 reports) (2160h ban)
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-05-07 00:08:39
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-05-06 10:05:49
(4 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
theanalogmaker
2026-05-05 02:00:23
(4 months ago)
CrowdSec: Symphony auto-ban: /api/v1 (100.0% confidence) (720h ban)
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-04 19:59:44
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (HEAD method ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (HEAD method)
Endpoint: /mysql_dump.sql
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ช
voormedia
2026-05-04 18:13:55
(4 months ago)
Accessed trap at '/actuator/env'
Web App Attack