๐ฉ๐ช
Roper123
2026-08-23 13:14:40
(1 day ago)
Web exploits
Web App Attack
Anonymous
2026-08-23 11:35:57
(1 day ago)
[23/Aug/2026:11:35:56 +0000] host=lovelyrender.app server=lovelyrender.app ip=212.32.69.253 method=G ...
show more
[23/Aug/2026:11:35:56 +0000] host=lovelyrender.app server=lovelyrender.app ip=212.32.69.253 method=GET req=/.env uri=/index.php status=302 bytes=5 rt=0.049 urt=0.049 ref="-" ua="Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
mieg
2026-08-23 10:48:13
(1 day ago)
Web vulnerability probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 10:37:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 06:37:01.971670 2026] [security2:error] [pid 8833:tid 8833] [client 212.32.69.253:31971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ndsbenefitconsulting.com"] [uri "/.env"] [unique_id "aorNTQ6V_HuGA0qYm5Bh4AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:23:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:23:18.944841 2026] [security2:error] [pid 30858:tid 30858] [client 212.32.69.253:63305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tdsdemo.com"] [uri "/.env"] [unique_id "aoq8BgQfGBzBWC2ENSeBUQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-08-23 05:39:45
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-08-23 05:24:00
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-08-23 05:15:19
(1 day ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 05:12:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:11:53.658932 2026] [security2:error] [pid 22771:tid 22771] [client 212.32.69.253:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "luisguacache.com"] [uri "/.env"] [unique_id "aoqBGQe6EcN6Nsn31U31AAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
wpadm3
2026-08-23 05:11:03
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-23 04:15:17
(1 day ago)
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
Anonymous
2026-08-23 04:13:34
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-08-23 04:10:01
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 04:09:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 212.32.69.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:09:40.706832 2026] [security2:error] [pid 23199:tid 23199] [client 212.32.69.253:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swarnar.com"] [uri "/.env"] [unique_id "aopyhOWIK3z0U4qbmNT2pQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xserverx.ru
2026-08-23 04:09:27
(1 day ago)
Honeypot triggered:
IP: 212.32.69.253
Request to: https://xserverx.ru/.env
Method: GET
Host: xserver ...
show more
Honeypot triggered:
IP: 212.32.69.253
Request to: https://xserverx.ru/.env
Method: GET
Host: xserverx.ru
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0
Referer: Direct
Country: US
ASN: Unknown
Triggered rules: (\.env|\.env\.local|\.env\.production)
Timestamp: 2026-08-23T04:09:26.293Z
show less
Hacking
Bad Web Bot
Web App Attack