๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 21:59:56
(14 hours ago)
Auto-ban: >3000 req/min op 2026-06-10
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-06-10 20:05:10
(16 hours ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-10 10:05:27
(1 day ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-04 06:05:49
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-03 03:05:37
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
Anonymous
2026-05-24 03:55:06
(2 weeks ago)
Web Probe / Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 11:43:12
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 07:43:05.964032 2026] [security2:error] [pid 22656:tid 22656] [client 172.70.80.8:12338] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.nancy-whittington.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.nancy-whittington.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ag2eSe5lEVJ0z4KdlOF6_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-05-12 19:01:52
(4 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /swagger.json
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-08 12:45:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 08:45:32.455359 2026] [security2:error] [pid 2466683:tid 2466683] [client 172.70.80.8:13992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mimrg.net"] [uri "/.env.production.local"] [unique_id "adZN7HYuyVyFhm7cS059PwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 14:17:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 10:17:37.619318 2026] [security2:error] [pid 288533:tid 288533] [client 172.70.80.8:11400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.gpaarch.com"] [uri "/.env2"] [unique_id "adUSAUZjbgXEKbLYWPWkvAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 06:16:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 02:16:02.234662 2026] [security2:error] [pid 1006555:tid 1006555] [client 172.70.80.8:13850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.stsis.me"] [uri "/.env.save"] [unique_id "adShIn_wg9RknMp01dP4hAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 18:43:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 14:43:24.685322 2026] [security2:error] [pid 421765:tid 421765] [client 172.70.80.8:11066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.medicalexchangeasinc.com"] [uri "/.env.example"] [unique_id "adP-zAVm0xSx1b1OKFDiBAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 17:35:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 13:34:57.499294 2026] [security2:error] [pid 227406:tid 227406] [client 172.70.80.8:9872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colbygrenier.com.jimgrenier.com"] [uri "/.env.dev"] [unique_id "adPuwWAMiuTUBBI3HWkmAwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 19:52:35
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 15:52:29.198733 2026] [security2:error] [pid 27721:tid 27721] [client 172.70.80.8:9516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.collectorcarconsultants.com"] [uri "/docker/.env.local"] [unique_id "adK9fSJkfg3ifQIRZgqeVAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 02:46:18
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 22:46:10.999672 2026] [security2:error] [pid 13725:tid 13725] [client 172.70.80.8:13965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.fynyx.com"] [uri "/.env.development"] [unique_id "adHM8mX0Q5N6aGYDR4033QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack