๐บ๐ธ
TPI-Abuse
2026-05-15 11:38:38
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:38:32.165648 2026] [security2:error] [pid 16106:tid 16186] [client 162.158.78.130:10527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ilenefletcher.com.richardleeweatherman.com"] [uri "/.env.save"] [unique_id "agcFuA0giuXA6RX0ZpjxTAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 10:16:45
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:15:36.426346 2026] [security2:error] [pid 16847:tid 16847] [client 162.158.78.130:9944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.covid19.mavikalem.org"] [uri "/.env.save"] [unique_id "agbySF4O9Y1UBenErhsyMgAAAAw"], referer: https://www.google.com/search?q=www.covid19.mavikalem.org
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:54:15
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:54:08.978315 2026] [security2:error] [pid 1778:tid 1778] [client 162.158.78.130:14112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.genesis-castle.com"] [uri "/.env.local"] [unique_id "agbDEJHMQKkdlb8F3TUb4AAAABE"], referer: https://www.google.com/search?q=webmail.genesis-castle.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 13:17:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 09:17:32.462049 2026] [security2:error] [pid 32736:tid 32736] [client 162.158.78.130:10281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.new-bethel-baptist-church.com"] [uri "/site/.env"] [unique_id "acaDbHvjKmJNkk9vVtLs2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 01:06:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 21:06:06.939712 2026] [security2:error] [pid 20954:tid 20954] [client 162.158.78.130:14234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aimer.es"] [uri "/.env.local"] [unique_id "acXX_jOgGg5pQtX1JCGaxAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 23:40:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 19:39:55.707850 2026] [security2:error] [pid 17568:tid 17568] [client 162.158.78.130:13342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.buildyourownpublishing.com"] [uri "/srv/.env"] [unique_id "acRyS0jnqwYLy8v4WPWnewAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 17:39:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 13:39:46.631081 2026] [security2:error] [pid 31635:tid 31635] [client 162.158.78.130:9928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cwidisplays.com"] [uri "/www/.env"] [unique_id "acQd4jr6iBFt1WEWw2Jb1QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 15:37:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.78.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 11:37:17.445481 2026] [security2:error] [pid 368:tid 385] [client 162.158.78.130:13375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.honorac.com"] [uri "/.env.example"] [unique_id "acQBLcsBYG-i8-A3uyixdgAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-21 03:05:39
(2 months ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-17 21:05:19
(2 months ago)
Scanning/Probing (27)
Brute-Force
Web App Attack
Anonymous
2025-09-03 01:10:02
(9 months ago)
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-09-01 05:10:45
(9 months ago)
Form spam
Web Spam
๐ฌ๐ง
pinguin
2025-08-17 01:25:45
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-07-19 14:29:40
(10 months ago)
wp admin page access attempt
...
Hacking
Web App Attack
๐บ๐ธ
mawan
2025-07-03 15:43:37
(11 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack