π§π¬
Stoyko Stoykov
2026-07-27 22:41:21
(5 hours ago)
172.70.175.25 - - [28/Jul/2026:01:41:20 +0300] "GET /small.php HTTP/1.1" 301 162 "-" "-"
...
Hacking
Web App Attack
Anonymous
2026-07-25 03:52:50
(3 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π©πͺ
SΓ©fora Srl
2026-07-07 08:02:11
(2 weeks ago)
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache ...
show more
Bad user agents ignoring web crawling rules. Draing bandwidth - detected by Fail2Ban in plesk-apache-badbot jail
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-15 06:24:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:21:56.891011 2026] [security2:error] [pid 32458:tid 32458] [client 172.70.175.25:10201] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nafsi-paris.mtalame.com"] [uri "/.env.development.local"] [unique_id "aga7hLBzKAv004R3O9sGnwAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-09 21:26:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 17:26:55.709011 2026] [security2:error] [pid 19072:tid 19072] [client 172.70.175.25:11811] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "winfield-intl.com"] [uri "/.git/config"] [unique_id "af-mnwUgPEI8Or-1lG86YAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
pinguin
2026-04-27 02:15:41
(3 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /config.js
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-07 10:45:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 06:45:19.618622 2026] [security2:error] [pid 899344:tid 899344] [client 172.70.175.25:13485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.braunhausmedia.com"] [uri "/.env.json"] [unique_id "adTgP7DrtQnLMUMT8V-lcAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 09:04:59
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 05:04:50.470877 2026] [security2:error] [pid 19734:tid 19734] [client 172.70.175.25:13065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.cityforsalefilm.com"] [uri "/.env.production.local"] [unique_id "adN3Mv_VnVgplk_zEnXPSQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 16:30:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 12:30:01.685192 2026] [security2:error] [pid 14990:tid 14990] [client 172.70.175.25:11556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaibeth.athome360.com"] [uri "/app/.env"] [unique_id "adE8iTimpmDiH4kPnsy8zwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 04:04:19
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 00:04:12.938051 2026] [security2:error] [pid 21481:tid 21481] [client 172.70.175.25:10190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sof.aarce.me"] [uri "/.env.local"] [unique_id "adCNvDXwrGLfmUXeOaAHUwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 12:36:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 08:36:07.942446 2026] [security2:error] [pid 5977:tid 5977] [client 172.70.175.25:9231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.uraniumjewelry.com"] [uri "/.env.prod"] [unique_id "ac-0N61Cflv4HNNP7KF9VAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 06:26:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 02:26:44.286262 2026] [security2:error] [pid 17874:tid 17874] [client 172.70.175.25:11150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.johnrobinsonconsulting.com"] [uri "/.env.bak"] [unique_id "ac9dpDVxwtn4Y8B2q0xZZQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 04:42:53
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 00:42:48.036763 2026] [security2:error] [pid 25411:tid 25411] [client 172.70.175.25:13059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lamineparke.com"] [uri "/.env.tmp"] [unique_id "ac9FSClQEBv_BT2V6sZ7-gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-03 03:40:19
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 23:40:13.045009 2026] [security2:error] [pid 29594:tid 29594] [client 172.70.175.25:11285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rewirenetworks.com"] [uri "/.env.dev.local"] [unique_id "ac82nf2_PTvDUGEXvauwMwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-02 21:12:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.25 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 17:12:08.870232 2026] [security2:error] [pid 3519:tid 3644] [client 172.70.175.25:9995] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hdtv55.com"] [uri "/.env.local"] [unique_id "ac7bqMnOqMfVxqcG8mVzhwAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack