๐ฌ๐ง
myintarweb
2026-08-15 00:13:03
(1 week ago)
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /.env.staging HTTP/1.1" 404 30013 "-" " ...
show more
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /.env.staging HTTP/1.1" 404 30013 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /config.env HTTP/1.1" 404 30013 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /.env.prod HTTP/1.1" 404 30013 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐น
matthew_eli
2026-07-01 06:45:14
(1 month ago)
Keenetic Firewall: Blocked Traffic (No Port Detected - likely UDP). Blocked 119 times in last 24h.
Port Scan
Anonymous
2026-07-01 04:37:33
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ต๐ฑ
srebrakowski.com
2026-06-30 19:18:50
(1 month ago)
crowdsec/waf-detected-exploits
Brute-Force
๐ฌ๐ง
myintarweb
2026-06-29 05:32:48
(1 month ago)
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /.env.staging HTTP/1.1" 404 30013 "-" " ...
show more
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /.env.staging HTTP/1.1" 404 30013 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /config.env HTTP/1.1" 404 30013 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
2a02:6ea0:5501::24 - - [29/Jun/2026:06:32:47 +0100] 443 "GET /.env.prod HTTP/1.1" 404 30013 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 05:21:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 01:21:44.739822 2026] [security2:error] [pid 29054:tid 29054] [client 2a02:6ea0:5501::24:56266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grasslakepizzatime.com"] [uri "/.env.local"] [unique_id "akIA6JUOy6udfdZ16BPbVAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 21:44:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 17:44:04.031691 2026] [security2:error] [pid 21664:tid 21664] [client 2a02:6ea0:5501::24:60642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koswerks.net"] [uri "/.env.production"] [unique_id "akGVpHd8uCGTuX9yCl26-wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-28 19:15:21
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-06-28 03:43:01
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
abuse-detection
2026-06-27 19:24:09
(1 month ago)
Web security detection (http-sensitive-probe); path=/.env.production; status=404
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 18:42:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 14:42:34.743578 2026] [security2:error] [pid 5969:tid 5969] [client 2a02:6ea0:5501::24:50763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anxo.net.anxo.org"] [uri "/.env"] [unique_id "akAZmlM_Pp_vX1zk-k_qKQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 15:09:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 11:09:27.244650 2026] [security2:error] [pid 26825:tid 26825] [client 2a02:6ea0:5501::24:51730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tomflynn.smilingorc.com"] [uri "/.env.prod"] [unique_id "aj_np6ZfDGDviW0inQLQ9QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 05:15:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:5501::24 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 01:15:22.490709 2026] [security2:error] [pid 13016:tid 13016] [client 2a02:6ea0:5501::24:51609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aguasolar.com"] [uri "/.env.prod"] [unique_id "aj9catxr6qN5aPLgD_KEYgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-06-23 20:47:35
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from PE.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from PE.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
XICTRON
2026-06-23 16:10:06
(2 months ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack