๐ฉ๐ช
big-cloud.nl
2026-08-28 19:10:19
(25 minutes ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:55:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:55:22.296864 2026] [security2:error] [pid 7177:tid 7177] [client 34.135.217.123:33256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terrencetorrent.nickmontfort.com"] [uri "/.env.prod"] [unique_id "apHLit3MLhtNtJg94R_BvgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 17:06:08
(2 hours ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:54:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:54:14.081739 2026] [security2:error] [pid 26058:tid 26058] [client 34.135.217.123:47936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valbreniscrivalbo.com"] [uri "/.env.backup"] [unique_id "apG9NmDu_J7-ZbsxOGfHmwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 16:42:09
(2 hours ago)
Web application firewall blocked 3 malicious HTTP requests. Port: 80,443 (HTTP/HTTPS). Attack types: ...
show more
Web application firewall blocked 3 malicious HTTP requests. Port: 80,443 (HTTP/HTTPS). Attack types: XSS/SQLi/exploit attempts. Timestamp: 1787935328.1678011 UTC. ASN: 396982 (GOOGLE-CLOUD-PLATFORM - Google LLC, US). All requests completed TCP 3-way handshake (verified via PROXY protocol).
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 16:20:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:20:38.859582 2026] [security2:error] [pid 24199:tid 24199] [client 34.135.217.123:41070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pandalearningcenters.com.stlouisdave.com"] [uri "/wp-config.php.bak"] [unique_id "apG1VlGoj9p6CxRvETNtVAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-08-28 16:17:20
(3 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.swp
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 15:14:51
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:14:47.241190 2026] [security2:error] [pid 14587:tid 14587] [client 34.135.217.123:50106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rahjx.net"] [uri "/wp-config.php.bak"] [unique_id "apGl59hNhTdWhpTq7dzP7gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:18:43
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:18:36.889027 2026] [security2:error] [pid 19663:tid 19686] [client 34.135.217.123:39664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.store.stonyp.com"] [uri "/wp-config.php.bak"] [unique_id "apGYvFxuzJ5IV_qL0tBPWwAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 13:45:04
(5 hours ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 13:41:18
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 13:36:33
(5 hours ago)
PSCSERV WPSCAN 34.135.217.123
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 13:19:05
(6 hours ago)
Attempt to access a backup or working file. Pattern match "\\\\. (920500-196)
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 12:55:02
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.135.217.123 (123.217.135.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:54:54.959631 2026] [security2:error] [pid 4959:tid 4959] [client 34.135.217.123:46188] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drhoss.com"] [uri "/.env.bak"] [unique_id "apGFHpopAW2NyhHzIjMzlgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 11:52:50
(7 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-197)
show less
Hacking