๐ซ๐ท
dynamix
2026-10-03 01:37:47
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-06 09:09:38
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 16:01:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 12:00:59.083415 2026] [security2:error] [pid 31909:tid 31909] [client 172.70.38.202:11891] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jackkerrart.com"] [uri "/.env.test"] [unique_id "apMCO73Qa8BPOMZjX4Ub3gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-17 21:59:53
(1 month ago)
Auto-ban: >3000 req/min op 2026-08-17
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-17 06:16:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:16:02.389832 2026] [security2:error] [pid 14716:tid 14716] [client 172.70.38.202:10305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.md20lf.org.ithacalions.com"] [uri "/.git/config"] [unique_id "aoKnIs-J5qFYzO4WWhyu7QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 08:09:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:08:57.680829 2026] [security2:error] [pid 11988:tid 11993] [client 172.70.38.202:13207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.scribblism.com"] [uri "/.git/config"] [unique_id "aoFwGcA2WIi_WzHEYnFKlwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-15 14:11:32
(1 month ago)
Web App Attack
๐ฌ๐ง
pinguin
2026-06-15 10:59:58
(3 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (POST method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-08 16:18:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 12:18:10.997325 2026] [security2:error] [pid 2319913:tid 2319913] [client 172.70.38.202:11470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "construction.bonefrog.com"] [uri "/admin/.env"] [unique_id "adZ_wiQzmLCT7R7iEGnIQwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 10:51:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 06:51:03.568344 2026] [security2:error] [pid 156077:tid 156077] [client 172.70.38.202:10898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.constructionloansfunding.com"] [uri "/.env.local"] [unique_id "adOQF62TjVgnmJIe-0L51gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 10:19:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 06:19:43.387719 2026] [security2:error] [pid 28642:tid 28642] [client 172.70.38.202:13390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.luxievintage.com"] [uri "/.env.example"] [unique_id "adOIv_5S3wD3-lvK-BzpQQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 04:13:00
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 00:12:56.885736 2026] [security2:error] [pid 19064:tid 19064] [client 172.70.38.202:12587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orchestrateyouraptitudes.com"] [uri "/.env.backup"] [unique_id "adMyyGmJTE1nFLn_on3AggAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 17:35:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 13:35:29.024295 2026] [security2:error] [pid 11472:tid 11472] [client 172.70.38.202:12292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valerieohayon.com"] [uri "/var/www/.env"] [unique_id "adKdYXDkU8IhECRrCZbMlQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 16:29:29
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 12:29:22.702573 2026] [security2:error] [pid 2196:tid 2227] [client 172.70.38.202:13522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ainavelas.com.venezuelaguia.com"] [uri "/config/.env.local"] [unique_id "adKN4t7dKXPADNe_ro1rcwAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 23:33:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.38.202 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 19:33:26.628306 2026] [security2:error] [pid 23348:tid 23348] [client 172.70.38.202:11585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.performingartsguild.com"] [uri "/.env.tmp"] [unique_id "adGfxgJwU3DfYR82x5GyewAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack