🇳🇱
WeCloudit-Anti-Abuse
2026-08-03 01:04:40
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-07-28 22:05:17
(1 month ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇩🇪
Hazzard
2026-07-28 21:21:52
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-07-27 23:42:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:42:18.125061 2026] [security2:error] [pid 1957206:tid 1957206] [client 2a09:bac5:9441:3af::5e:5d:34118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.i-slim.net"] [uri "/.env"] [unique_id "amfs2r2HmMsgR29_tjV3JQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-25 03:24:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:24:45.685088 2026] [security2:error] [pid 1029504:tid 1029504] [client 2a09:bac5:9441:3af::5e:5d:35878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jasonharveydesign.dianogah.com"] [uri "/.env"] [unique_id "amQsfQViqLnGyteswFvkpQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-07-25 02:52:01
(1 month ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 21:51:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 17:51:04.522009 2026] [security2:error] [pid 3419953:tid 3419953] [client 2a09:bac5:9441:3af::5e:5d:58366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.finishlineenterprisesllc.com"] [uri "/.env.local"] [unique_id "amKMyHZIsYAo8PkYsXO-pgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 21:01:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 17:01:14.354025 2026] [security2:error] [pid 3545345:tid 3545345] [client 2a09:bac5:9441:3af::5e:5d:34072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sessionsdispensary.com.modeltdr.com"] [uri "/.env"] [unique_id "amKBGlnxSfTiNdBM89uH9QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 20:37:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 16:37:23.254427 2026] [security2:error] [pid 2714669:tid 2714669] [client 2a09:bac5:9441:3af::5e:5d:35860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.thingstodonude.com"] [uri "/.env"] [unique_id "amJ7gyRkPDIhhNn-I0YQagAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 19:58:07
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 15:58:01.251372 2026] [security2:error] [pid 3502204:tid 3502204] [client 2a09:bac5:9441:3af::5e:5d:54140] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "tribalgamingtech.com"] [uri "/.env"] [unique_id "amJySZP4W7kwyYD-uWw-XAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2026-07-23 19:40:43
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.kube/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
gadix
2026-07-23 19:11:57
(1 month ago)
[23/Jul/2026:21:11:56.613240 +0200] amJnfMYdVwvsFdRWcSN3kwAAAAA 2a09:bac5:9441:3af::5e:5d 49106 127. ...
show more
[23/Jul/2026:21:11:56.613240 +0200] amJnfMYdVwvsFdRWcSN3kwAAAAA 2a09:bac5:9441:3af::5e:5d 49106 127.0.0.1 7081
[23/Jul/2026:21:11:56.789500 +0200] amJnfB8_66Ao2qUCubMM4AAAABE 2a09:bac5:9441:3af::5e:5d 49140 127.0.0.1 7081
[23/Jul/2026:21:11:56.889263 +0200] amJnfDsmZikr4j02z3XeTAAAABA 2a09:bac5:9441:3af::5e:5d 49162 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 19:10:31
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 15:10:23.561108 2026] [security2:error] [pid 2673203:tid 2673203] [client 2a09:bac5:9441:3af::5e:5d:53748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.alexthepunk.com"] [uri "/.env"] [unique_id "amJnHxVnqNTggYGvuTxZ4QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-07-23 18:55:54
(1 month ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 18:45:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9441:3af::5e:5d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 14:45:32.757062 2026] [security2:error] [pid 3644058:tid 3644058] [client 2a09:bac5:9441:3af::5e:5d:59722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.chitsey.com"] [uri "/.env"] [unique_id "amJhTJhvW2qSOuLmudMcCgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack