๐ซ๐ท
dynamix
2026-06-25 02:44:59
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:01:47
(4 months ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐ซ๐ท
loveprod
2026-04-17 01:20:01
(4 months ago)
162.158.62.6 - - [17/Apr/2026:04:20:00 +0300] "GET /.env.staging HTTP/2.0" 403 553 "-" "Mozilla/5.0 ...
show more
162.158.62.6 - - [17/Apr/2026:04:20:00 +0300] "GET /.env.staging HTTP/2.0" 403 553 "-" "Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
162.158.62.6 - - [17/Apr/2026:04:20:00 +0300] "GET /.env.production.local HTTP/2.0" 403 553 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
๐ฌ๐ง
pinguin
2026-04-05 23:20:40
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
abdubhai
2026-03-25 16:26:58
(5 months ago)
162.158.62.6 - - [25/Mar/2026:21
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-21 05:36:01
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 01:35:52.150928 2026] [security2:error] [pid 20076:tid 20076] [client 162.158.62.6:9651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cs.cswiki.us"] [uri "/.env.save"] [unique_id "ab4uOCu4_n_g0_s42nY7IgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 02:04:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 22:04:22.559461 2026] [security2:error] [pid 27227:tid 27227] [client 162.158.62.6:9398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pathpointexec.com.pathpointservices.com"] [uri "/api/.env"] [unique_id "ab38poXT2W0xIxCIb3cGbAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:22:29
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:22:20.811826 2026] [security2:error] [pid 8642:tid 8642] [client 162.158.62.6:13188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.emhelectric.com"] [uri "/.env.dev"] [unique_id "ab3kvEIqUvETvMKkAzW8eQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:04:28
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:04:21.689813 2026] [security2:error] [pid 29712:tid 29712] [client 162.158.62.6:9605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bowdens-landingcom.draindoctor.us"] [uri "/.env.docker"] [unique_id "abzjZYKk5Os_jowRMzr8PwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:19:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:19:14.857303 2026] [security2:error] [pid 23079:tid 23079] [client 162.158.62.6:11144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.insurance4you.agency"] [uri "/config/.env"] [unique_id "abyuolVr-ymcEv5T2uB-9gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:59:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:59:12.809650 2026] [security2:error] [pid 1806:tid 1806] [client 162.158.62.6:12171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.astrologydemo.com"] [uri "/www/.env"] [unique_id "abyp8M9_0VZQX3EYkKtvVQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:54:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:54:31.853642 2026] [security2:error] [pid 2210086:tid 2210086] [client 162.158.62.6:13941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.debzy.com"] [uri "/.env_backup"] [unique_id "abyax_WxmnlqXRGrkP2UcQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-03-19 14:11:07
(5 months ago)
162.158.62.6 - - [19/Mar/2026:19
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-19 11:46:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:46:14.123857 2026] [security2:error] [pid 12547:tid 12547] [client 162.158.62.6:11179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fatjesus.com.sparler.com"] [uri "/.env.development.local"] [unique_id "abviBge1zHhzpAjqXhmcNAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:19:00
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.62.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:18:54.344902 2026] [security2:error] [pid 5027:tid 5027] [client 162.158.62.6:12967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.deniz-bilgisayar.com"] [uri "/private/.env"] [unique_id "abvNjuN-fYy6dmO-dNtWFwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack