π¬π§
pinguin
2026-06-03 17:26:40
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (POST method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (POST method)
Endpoint: /graphql
UA: Mozilla/5.0 (l9scan/2.0.8393e27323e28313e2430313; +https://leakix.net)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¬π§
Axel
2026-05-08 23:48:03
(4 weeks ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env.dev Ser ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env.dev Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
Anonymous
2026-05-01 20:20:43
(1 month ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
π¨π
4server
2026-04-20 18:23:20
(1 month ago)
[MonApr2020:23:15.6402832026][security2:error][pid2073856:tid2073894][client162.158.154.81:0]ModSecu ...
show more
[MonApr2020:23:15.6402832026][security2:error][pid2073856:tid2073894][client162.158.154.81:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mondocaneticino.ch\"][uri\"/terraform.tfvars\"][unique_id\"aeZvE4uN2gPiHGKDrhSFzAAAAQY\"]
show less
Hacking
Web App Attack
πΊπΈ
oncord
2026-04-14 16:26:35
(1 month ago)
Form spam
Web Spam
πΊπΈ
octageeks.com
2026-04-04 04:45:32
(2 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-21 00:40:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:40:23.477597 2026] [security2:error] [pid 9454:tid 9466] [client 162.158.154.81:10853] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.alisalholdings.oconnorpest.biz"] [uri "/.env.bak"] [unique_id "ab3o9xofiqXaVxW2KS2yggAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-20 04:10:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:10:27.743369 2026] [security2:error] [pid 32082:tid 32082] [client 162.158.154.81:12379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bgraph.com"] [uri "/www/.env"] [unique_id "abzIs2TtuGLXfxLWyw9WgwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
ISPLtd
2026-03-19 18:02:38
(2 months ago)
162.158.154.81 - - [19/Mar/2026:15:02:37 -0300] "GET /.env.dev.local
162.158.154.81 - - [19/Mar/2026 ...
show more
162.158.154.81 - - [19/Mar/2026:15:02:37 -0300] "GET /.env.dev.local
162.158.154.81 - - [19/Mar/2026:15:02:37 -0300] "GET /web/.env
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:26:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:25:58.964592 2026] [security2:error] [pid 14041:tid 14041] [client 162.158.154.81:9787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.willowstick-carbon.com"] [uri "/.env.backup"] [unique_id "abvdRqk1VaxmSRxKxo5nRwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 11:01:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:01:37.792959 2026] [security2:error] [pid 12965:tid 12965] [client 162.158.154.81:10991] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "footshufflerz.com"] [uri "/docker/.env"] [unique_id "abvXkc4nkBx7iD3pyetQ7wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:25:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:25:30.290041 2026] [security2:error] [pid 4960:tid 4960] [client 162.158.154.81:12503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hcadwin.com"] [uri "/var/www/.env"] [unique_id "abvPGpoFMofX6A0qJGrTfwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 10:05:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:05:39.999781 2026] [security2:error] [pid 29369:tid 29369] [client 162.158.154.81:12895] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.willowgrovemusic.com"] [uri "/private/.env"] [unique_id "abvKc65Z3ZeG8t8euhpMuQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 09:37:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:37:03.644096 2026] [security2:error] [pid 32734:tid 32734] [client 162.158.154.81:9385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jessemeyersconsulting.com"] [uri "/.env.test"] [unique_id "abvDv2Lw0BwC2OHfQWaFUAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-19 09:19:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.154.81 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 05:19:18.727463 2026] [security2:error] [pid 24327:tid 24327] [client 162.158.154.81:9662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mmldesign.com"] [uri "/public/.env"] [unique_id "abu_llbTa-QoqlbxfBv6pQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack