๐ณ๐ฑ
homeshowdomain.nl
2026-10-07 21:59:22
(4 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-06.
show less
Web App Attack
SSH
Hacking
๐น๐ท
oalver
2026-10-06 23:55:03
(1 day ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.env (HTTP 404). First seen: 2026-10-06. Risk score: 30/100.
show less
Web App Attack
๐ง๐ท
radardatelecom
2026-10-06 22:27:03
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-06 21:59:51
(1 day ago)
Auto-ban: >3000 req/min op 2026-10-06
Web App Attack
SSH
Hacking
๐จ๐ญ
lufi
2026-10-06 21:52:18
(1 day ago)
2026-10-06T23:52:18+02:00 lufischer04 ids442 2026-10-06 23:52:18 199.127.61.36: blacklistedPath: /.e ...
show more
2026-10-06T23:52:18+02:00 lufischer04 ids442 2026-10-06 23:52:18 199.127.61.36: blacklistedPath: /.env
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:49:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:49:31.793477 2026] [security2:error] [pid 7282:tid 7282] [client 199.127.61.36:52557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.admin.casaniagara.com.mx.elpais.mx"] [uri "/.env"] [unique_id "asVs6-xeMaOSxuS2l7elSwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-06 21:31:03
(1 day ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:09:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:09:46.835880 2026] [security2:error] [pid 6406:tid 6406] [client 199.127.61.36:55736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dcounty.com"] [uri "/.env"] [unique_id "asVjmksRyQK04qwr-symVwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-10-06 21:04:18
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/web-asn-lockdown-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:16:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:16:14.388522 2026] [security2:error] [pid 18256:tid 18276] [client 199.127.61.36:51860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aafminstitute.com"] [uri "/.env"] [unique_id "asVXDksmaZ_VUrkxiI4YfwAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
kie
2026-10-06 19:34:38
(1 day ago)
06-10-2026:19:34:03UTC [Nginx Web Server] Suspicious web request: path:/.env (481 request(s)).
Bad Web Bot
Web App Attack
๐บ๐ธ
Epimetheus
2026-10-06 19:30:37
(1 day ago)
Unauthorized access attempts:
[GET] /.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi ...
show more
Unauthorized access attempts:
[GET] /.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
show less
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-10-06 19:24:02
(1 day ago)
vulnerability scan
Web App Attack
๐ซ๐ฎ
as211431.net
2026-10-06 19:02:08
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 18:28:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 199.127.61.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 14:28:20.561241 2026] [security2:error] [pid 29062:tid 29090] [client 199.127.61.36:57038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nrgla.com"] [uri "/.env"] [unique_id "asU9xOtK9sEL4kX-ihEKDgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack