Anonymous
2026-10-11 10:55:57
(24 minutes ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-11 10:26:14
(54 minutes ago)
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 158.94.209.189 - - [11/Oct/2026:12:26:04 +0200] "GET /.env HTTP/1.1" 301 735 "-" "python-requests/2.34.2"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-11 09:09:57
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 158.94.209.189 (-): N in the last X secs
Web App Attack
๐ฉ๐ช
conseilgouz
2026-10-11 04:48:38
(6 hours ago)
coe-17 : Block hidden directories=>/.env(/)
Hacking
๐ณ๐ฑ
Mangelot Hosting
2026-10-11 02:00:30
(9 hours ago)
(web_sensitive_file) srv103 Sensitive file probe (.env/.git/backup) 158.94.209.189 (NL/The Netherlan ...
show more
(web_sensitive_file) srv103 Sensitive file probe (.env/.git/backup) 158.94.209.189 (NL/The Netherlands/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฟ
realstuffie
2026-10-11 01:01:03
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
Anonymous
2026-10-10 20:41:54
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ซ๐ฎ
as211431.net
2026-10-10 19:20:52
(16 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.save
UA: python-requests/2.34.2
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ฎ
Rauno Asp
2026-10-10 18:18:37
(17 hours ago)
Malicious scanning/exploit attempt detected on elbasanapartments.al (fail2ban jail: webattack)
Web App Attack
๐บ๐ธ
swalluw
2026-10-10 18:03:29
(17 hours ago)
Web vulnerability scanning: request for /.env (HTTP 404, GET) at 2026-10-10T18:03:29+00:00 - exploit ...
show more
Web vulnerability scanning: request for /.env (HTTP 404, GET) at 2026-10-10T18:03:29+00:00 - exploit probe, no legitimate use
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 21:50:12
(1 day ago)
Automatically blocked after 7 security events. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 7 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 21:11:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 158.94.209.189 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 158.94.209.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:11:28.000988 2026] [security2:error] [pid 21975:tid 21975] [client 158.94.209.189:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kryptonome.com"] [uri "/.env"] [unique_id "aslYgISPARnVm4IeQQrR0QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Aurealize
2026-10-09 20:25:35
(1 day ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.env.
Web App Attack
Hacking
๐ณ๐ฑ
Mangelot Hosting
2026-10-09 19:24:52
(1 day ago)
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 158.94.209.189 (NL/The Netherlan ...
show more
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 158.94.209.189 (NL/The Netherlands/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
iwle
2026-10-09 17:58:22
(1 day ago)
[Fri Oct 09 13:58:16.900702 2026] [:error] [pid 1478:tid 1575] [client 158.94.209.189:0] [client 158 ...
show more
[Fri Oct 09 13:58:16.900702 2026] [:error] [pid 1478:tid 1575] [client 158.94.209.189:0] [client 158.94.209.189] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "autodiscover.ufscards.com"] [uri "/.env"] [unique_id "askrOK3nn8hvTBDp0D9Z6gAAAI4"]
[Fri Oct 09 13:58:20.738200 2026] [:error] [pid 1477:tid 1602] [client 158.94.209.189:0] [client 158.94.209.189] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line
...
show less
Web App Attack