π¬π§
pinguin
2026-05-14 11:55:17
(3 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-05-13 06:26:15
(3 weeks ago)
Web App Attack
Brute-Force
Web App Attack
πΊπΈ
wimaxnz
2026-04-08 02:13:47
(2 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
πΊπΈ
mnsf
2026-04-03 05:06:00
(2 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-03-31 03:06:00
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-03-30 01:05:44
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-27 09:41:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 05:41:48.758116 2026] [security2:error] [pid 12309:tid 12309] [client 162.158.79.13:11655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.groux.net"] [uri "/.env.backup"] [unique_id "acZQ3EZW7QkUhw80_kDV4AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-27 02:40:49
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 22:40:39.520476 2026] [security2:error] [pid 21326:tid 21326] [client 162.158.79.13:10252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.gwenwaltersartrep.com"] [uri "/.env2"] [unique_id "acXuJ_Zoy0SjJHWh1_uRMwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 13:32:12
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 09:32:06.777957 2026] [security2:error] [pid 25258:tid 25258] [client 162.158.79.13:9953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.silvermoonpizza.com"] [uri "/config/.env.local"] [unique_id "acU1VkZoRAgPYuokjsMFGQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 12:24:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 08:23:50.125170 2026] [security2:error] [pid 14503:tid 14503] [client 162.158.79.13:12346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.landscapedesignworkshop.com"] [uri "/.env.test"] [unique_id "acUlVgjRTpcgIO8AYlTinwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 07:19:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 03:19:21.101450 2026] [security2:error] [pid 3346:tid 3419] [client 162.158.79.13:13770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.baronlongford.com"] [uri "/.env.bak"] [unique_id "acTd-Yb3XSmT9wcd7sE91QAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-26 00:01:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 20:01:26.786508 2026] [security2:error] [pid 1380:tid 1380] [client 162.158.79.13:13734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.application.oxfordgliding.com"] [uri "/.env.production.bak"] [unique_id "acR3Vhn7mnOYoT20BzL1DAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-25 20:56:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 16:56:29.838195 2026] [security2:error] [pid 29745:tid 29745] [client 162.158.79.13:12113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achillespress.com.tandm.us"] [uri "/.env.production"] [unique_id "acRL_WI1WLS9foVpbOlbwwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-25 15:38:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 11:38:41.289134 2026] [security2:error] [pid 986:tid 989] [client 162.158.79.13:9901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.honorac.com"] [uri "/.env.save"] [unique_id "acQBgTPDgrIgzQznXTvBTQAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-03-21 00:08:42
(2 months ago)
Scanning/Probing (24)
Brute-Force
Web App Attack