๐บ๐ธ
TPI-Abuse
2026-09-29 04:27:52
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 00:27:46.518667 2026] [security2:error] [pid 25453:tid 25453] [client 162.158.63.177:10615] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gpahomeinspections.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gpahomeinspections.com"] [uri "/index.php.bak"] [unique_id "ars-QqBCP-SnK5qgecEIVQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 17:33:34
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 13:33:30.244817 2026] [security2:error] [pid 17723:tid 17723] [client 162.158.63.177:14311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||johnheinrich.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "johnheinrich.com"] [uri "/index.php.bak"] [unique_id "arqk6pqrbCxBc6S9maQe2AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
robotstxt
2026-09-21 16:46:20
(1 week ago)
162.158.63.177 - - [21/Sep/2026:16:45:43 +0000] "GET /htdocs/.env HTTP/2.0" 403 2 "-" "Mozilla/5.0 ( ...
show more
162.158.63.177 - - [21/Sep/2026:16:45:43 +0000] "GET /htdocs/.env HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.150.243.73" edge="162.158.63.177"
162.158.63.177 - - [21/Sep/2026:16:45:44 +0000] "GET /www/.env HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.150.243.73" edge="162.158.63.177"
162.158.63.177 - - [21/Sep/2026:16:45:50 +0000] "GET /html/.env HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.150.243.73" edge="162.158.63.177"
162.158.63.177 - - [21/Sep/2026:16:45:51 +0000] "GET /live/.env HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.150.243.73" edge="162.158.63.177"
162.158.63.177 - - [21/Sep/2026
...
show less
Web App Attack
๐ง๐ช
madeit
2026-09-17 06:47:00
(1 week ago)
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-08-15 10:27:56
(1 month ago)
162.158.63.177 - - [15/Aug/2026:13:27:54 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (l9sca ...
show more
162.158.63.177 - - [15/Aug/2026:13:27:54 +0300] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (l9scan/2.0.33e27393e2431313e2838313; +https://leakix.net)"
...
show less
Hacking
Web App Attack
๐ง๐ท
mateus.vicente
2026-08-01 09:07:57
(1 month ago)
[2026-08-01T09:07:57Z] Requests to sensitive Apache endpoints and path traversal patterns. (srv-app)
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-18 02:05:40
(3 months ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: US / AS13335 Cloudflare, Inc.
Active: 02:05:10 UTC
Volume: 1 HTTP req
Probed: /
Status mix: 444ร1
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-05-18 22:09:25
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /aws-exports.js
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
pinguin
2026-04-30 09:13:49
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /aws-exports.js
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-21 03:07:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:07:52.315212 2026] [security2:error] [pid 6256:tid 6256] [client 162.158.63.177:11401] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kerrywelt.com"] [uri "/.env.example"] [unique_id "ab4LiH7FtelWG6KVlo1s5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:48:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:48:25.439507 2026] [security2:error] [pid 25378:tid 25378] [client 162.158.63.177:10508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eta-mct.com"] [uri "/.env.development.local"] [unique_id "ab346U8i72UaZnqMsPShjwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:25:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:25:16.420471 2026] [security2:error] [pid 10116:tid 10116] [client 162.158.63.177:10094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.emhelectric.com"] [uri "/.env.dev"] [unique_id "ab3lbAOhn7RScxPdDR86BwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:39:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:39:35.908307 2026] [security2:error] [pid 23382:tid 23382] [client 162.158.63.177:12113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.richardlyne.com"] [uri "/site/.env"] [unique_id "abz5t7EY7_yQSUfmnTUBrwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:21:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:20:59.849040 2026] [security2:error] [pid 7293:tid 7293] [client 162.158.63.177:14168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pintoresdecasascdmx.com"] [uri "/.env_secret"] [unique_id "abzLK-QgWczbawS5raZKQQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:21:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.63.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:20:57.431584 2026] [security2:error] [pid 18744:tid 18744] [client 162.158.63.177:13437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brazilianbottom.com"] [uri "/backend/.env"] [unique_id "aby9GfOB15ANAKnpo2vE2gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack