๐บ๐ธ
TPI-Abuse
2026-05-16 11:18:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 07:18:43.014642 2026] [security2:error] [pid 5610:tid 5610] [client 149.143.137.14:47393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nadepot.nodepot.com"] [uri "/api/.env"] [unique_id "aghSk2yd4Aqwnc8VDo0BIQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:42:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:41:43.371902 2026] [security2:error] [pid 20655:tid 20674] [client 149.143.137.14:59687] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebiglies.org"] [uri "/.git/objects/"] [unique_id "agbcRwS8NqowuojCS1O73gAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:20:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:20:01.907244 2026] [security2:error] [pid 4647:tid 4647] [client 149.143.137.14:56179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deniz-bilgisayar.com"] [uri "/.env.stage"] [unique_id "agbXMSGsPRVGQTWrVCMNMgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:01:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:01:28.271905 2026] [security2:error] [pid 20494:tid 20494] [client 149.143.137.14:60771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "macro-astrology.com"] [uri "/.env.backup"] [unique_id "agbS2HwNl3BhqF369_3nYwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:40:15
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:39:55.747665 2026] [security2:error] [pid 12359:tid 12359] [client 149.143.137.14:47699] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cabwebs.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cabwebs.com"] [uri "/config/master.key"] [unique_id "agbNyxdu94MeTviWf_wXtQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 12:46:19
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 08:45:46.563292 2026] [security2:error] [pid 16811:tid 16811] [client 149.143.137.14:43633] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||sheamar.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sheamar.com"] [uri "/db.sql"] [unique_id "agMg-tw9LnqV_PnCvziaLwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-08 23:38:16
(3 months ago)
(caddyscan) Scanner path probe from 149.143.137.14 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.137.14 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 990754370532wildcardprobe-1777020811057846024.bicities.org 200 2627 149.143.137.14 - - [08/May/2026:23:23:26 +0000] "GET /backend/.env HTTP/1.1"
0866042200.wildcardprobe-1777273075586940549.bicities.org 200 0 149.143.137.14 - - [08/May/2026:23:38:09 +0000] "HEAD /root/.aws/credentials HTTP/1.1"
0866042200.wildcardprobe-1777273075586940549.bicities.org 200 0 149.143.137.14 - - [08/May/2026:23:38:09 +0000] "HEAD /.aws/credentials HTTP/1.1"
0866042200.wildcardprobe-1777273075586940549.bicities.org 200 0 149.143.137.14 - - [08/May/2026:23:38:09 +0000] "HEAD /root/.aws/config HTTP/1.1"
0866042200.wildcardprobe-1777273075586940549.bicities.org 200 2627 149.143.137.14 - - [08/May/2026:23:38:12 +0000] "GET /.aws/credentials HTTP/1.1"
show less
Port Scan
๐บ๐ธ
Matthew Ping
2026-05-08 07:45:01
(3 months ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-07 21:15:08
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 17:14:56.101782 2026] [security2:error] [pid 4595:tid 4595] [client 149.143.137.14:38465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "surrenderhouse.com"] [uri "/.env.development"] [unique_id "af0A0NA_ZZd5mqj4Gl1LxgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-07 00:17:48
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
ArturShelby
2026-05-05 19:27:28
(3 months ago)
Honeypot triggered: /root/.gitconfig
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-05-05 06:47:18
(4 months ago)
Unidentified crawler ignoring robots.txt: 149.143.137.14 - - [05/May/2026:08:46:54 +0200] "GET /.env ...
show more
Unidentified crawler ignoring robots.txt: 149.143.137.14 - - [05/May/2026:08:46:54 +0200] "GET /.env.preview HTTP/2.0" 301 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15" asn=7029 org="Windstream Communications LLC"
149.143.137.14 - - [05/May/2026:08:46:55 +0200] "HEAD /root/.s3cfg HTTP/2.0" 404 0 "https://www.stateparl.de/root/.s3cfg" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0" asn=7029 org="Windstream Communications LLC"
149.143.137.14 - - [05/May/2026:08:46:56 +0200] "GET /.env.qa HTTP/2.0" 404 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:125.0) Gecko/20100101 Firefox/125.0" asn=7029 org="Windstream Communications LLC"
...
show less
Bad Web Bot
๐ซ๐ฎ
as211431.net
2026-05-04 19:59:43
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (HEAD method ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (HEAD method)
Endpoint: /credentials.ini
UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
mnsf
2026-05-04 14:05:15
(4 months ago)
Scanning/Probing (22)
Brute-Force
Web App Attack
Anonymous
2026-05-04 11:05:16
(4 months ago)
Blocked: Reason='Suspicious traffic score=70 (review-based detection)'; Requests=14
Hacking