🇳🇱
homeshowdomain.nl
2026-08-29 22:00:21
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
🇬🇧
Aetherweb Ark
2026-08-29 03:22:42
(21 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.121.163.167 (US/United States/167.163.121.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.121.163.167 (US/United States/167.163.121.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇲🇾
Rizzy
2026-08-29 02:19:46
(22 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇩🇪
Marc
2026-08-29 01:44:28
(23 hours ago)
34.121.163.167 - - [29/Aug/2026:03:44:28 +0200] "GET /.env.prod HTTP/1.1" 404 4617 "-" "crusader-wor ...
show more
34.121.163.167 - - [29/Aug/2026:03:44:28 +0200] "GET /.env.prod HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.121.163.167 - - [29/Aug/2026:03:44:28 +0200] "GET /.env.production HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 34.121.163.167 - - [29/Aug/2026:03:44:28 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 4617 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇸
1gz
2026-08-29 01:06:19
(23 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php~
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-29 00:53:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:53:30.992777 2026] [security2:error] [pid 25628:tid 25628] [client 34.121.163.167:41878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hierrosbernal.com"] [uri "/.env.dev"] [unique_id "apItimwiP18nWkiXpOoMhwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 00:40:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇪🇸
Francisco Vallejo
2026-08-29 00:31:54
(1 day ago)
[Sat Aug 29 02:31:53.289996 2026] [core:info] [pid 1331827:tid 140579136579264] [client 34.121.163.1 ...
show more
[Sat Aug 29 02:31:53.289996 2026] [core:info] [pid 1331827:tid 140579136579264] [client 34.121.163.167:39752] AH00128: File does not exist: /var/www/franvallejo/storage/logs/laravel.log
[Sat Aug 29 02:31:53.415048 2026] [core:info] [pid 1331827:tid 140578641671872] [client 34.121.163.167:39752] AH00128: File does not exist: /var/www/franvallejo/.env
[Sat Aug 29 02:31:53.525712 2026] [core:info] [pid 1331827:tid 140580015298240] [client 34.121.163.167:39752] AH00128: File does not exist: /var/www/franvallejo/.env.local
[Sat Aug 29 02:31:53.635939 2026] [core:info] [pid 1331827:tid 140580143212224] [client 34.121.163.167:39752] AH00128: File does not exist: /var/www/franvallejo/.env.production
[Sat Aug 29 02:31:53.918663 2026] [core:info] [pid 1331827:tid 140579178542784] [client 34.121.163.167:39752] AH00128: File does not exist: /var/www/franvallejo/.env.prod
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-29 00:26:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:26:21.465898 2026] [security2:error] [pid 29807:tid 29922] [client 34.121.163.167:57634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rudimentseq.com"] [uri "/.env.local"] [unique_id "apInLVF6rbOZPGj_8EmFJwAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:08:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:08:30.264433 2026] [security2:error] [pid 106473:tid 106500] [client 34.121.163.167:50780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.apkatten.merart.com"] [uri "/.env"] [unique_id "apIi_gT0nhezPdooEOmVzgAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-08-29 00:08:31
(1 day ago)
Abuse Detected (15)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:34:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:34:34.280867 2026] [security2:error] [pid 14619:tid 14619] [client 34.121.163.167:52418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bienvista.com"] [uri "/wp-config.php~"] [unique_id "apIbCq-M4HyPw2bM1ZbUlgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-08-28 23:03:07
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-08-28 23:02:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:02:46.931908 2026] [security2:error] [pid 11421:tid 11421] [client 34.121.163.167:38962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wookheo.com"] [uri "/.env.production"] [unique_id "apITlnpWATZW5chdkIdWFwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:41:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.121.163.167 (167.163.121.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:41:37.342305 2026] [security2:error] [pid 11971:tid 11971] [client 34.121.163.167:53478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janaia.com.yubagals.com"] [uri "/.env.backup"] [unique_id "apIOoc8NrXdJ13R4IWSHwgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack