๐ฌ๐ง
Aetherweb Ark
2026-05-11 20:55:34
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 176.65.139.238 (LU/Luxembourg/-): N in the last ...
show more
(mod_security) mod_security (id:949110) triggered by 176.65.139.238 (LU/Luxembourg/-): N in the last X secs
show less
Web App Attack
Anonymous
2026-05-11 20:50:11
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-05-11 20:50:08
(3 weeks ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ง๐ท
Halux
2026-05-11 20:47:41
(3 weeks ago)
176.65.139.238 Probing protected path or service
Web App Attack
๐บ๐ธ
SLSLLC
2026-05-11 20:47:39
(3 weeks ago)
176.65.139.238 - - [11/May/2026:20:47:38 +0000] "GET /app/.env HTTP/1.1" 403 4690 "-" "Mozilla/5.0 ( ...
show more
176.65.139.238 - - [11/May/2026:20:47:38 +0000] "GET /app/.env HTTP/1.1" 403 4690 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-05-11 20:45:22
(3 weeks ago)
Probing websites for vulnerabilities
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-05-11 20:45:19
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 34). Ip 176.65.139.238 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2026-05-11 20:45:18.557385157 +0000 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
interbiznw.com
2026-05-11 20:42:36
(3 weeks ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-05-11 20:39:40
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
pinguin
2026-05-11 20:39:17
(3 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /app/.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐พ
lns.bz
2026-05-11 20:33:41
(3 weeks ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 20:33:17
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 176.65.139.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 176.65.139.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 16:33:12.497214 2026] [security2:error] [pid 30443:tid 30443] [client 176.65.139.238:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodrigoaldecoa.com"] [uri "/app/.env"] [unique_id "agI9CLIgKGzmdo6DMp7LZAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-05-11 20:30:32
(3 weeks ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /app/.env Ser ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /app/.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
JustMeHere
2026-05-11 20:24:34
(3 weeks ago)
[Mon May 11 16:24:25.766888 2026] [security2:error] [pid 3810:tid 3861] [client 176.65.139.238:40756 ...
show more
[Mon May 11 16:24:25.766888 2026] [security2:error] [pid 3810:tid 3861] [client 176.65.139.238:40756] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mail.yorknation.com"] [uri "/app/.env"] [unique_id "agI6-e_F1F15DWasHLMD1gAAARc"]
...
show less
Web App Attack
๐ฉ๐ช
Holger
2026-05-11 20:22:41
(3 weeks ago)
URL probing: GET /app/.env
Web App Attack