🇺🇸
TPI-Abuse
2026-09-06 15:09:14
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.143.165.69 (69.165.143.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.165.69 (69.165.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:09:11.239398 2026] [security2:error] [pid 30366:tid 30366] [client 34.143.165.69:46376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mathewyoung.com"] [uri "/api/fs/read"] [unique_id "ap2CF8iRGhhrchhe5_2nBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WizardsToolkit
2026-09-06 14:52:52
(55 minutes ago)
tried to access forbidden files; attempted to access /@fs/app/.env?import&raw??
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:48:04
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.143.165.69 (69.165.143.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.143.165.69 (69.165.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:47:54.644398 2026] [security2:error] [pid 8173:tid 8173] [client 34.143.165.69:47716] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kairoslogammakmur.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kairoslogammakmur.com"] [uri "/z9x8c7v6b5-debug-trigger-kairoslogammakmur.com"] [unique_id "ap1vCl1AFWmdbFwB7R2msQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-09-06 13:33:49
(2 hours ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /files../.env
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
Ilop
2026-09-06 12:30:13
(3 hours ago)
[hp-100] 4 unsolicited packets to honeypot ports 8443,80,8080,443 (OCI DShield sensor)
Port Scan
🇺🇸
interbiznw.com
2026-09-06 12:16:22
(3 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
🇩🇪
arnisolutions
2026-09-06 12:10:54
(3 hours ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-06 and 2026-09-06 (UTC). Sample request: GET /.env?import&raw HTTP/2.0
show less
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-06 10:44:50
(5 hours ago)
20 attempts against mh-misbehave-ban on melon
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-06 10:22:19
(5 hours ago)
Suspicious URL access.
Web App Attack
Anonymous
2026-09-06 10:07:04
(5 hours ago)
Automated web scanner. Requested suspicious paths: /z9x8c7v6b5-debug-trigger-app.tigzig.com | /confi ...
show more
Automated web scanner. Requested suspicious paths: /z9x8c7v6b5-debug-trigger-app.tigzig.com | /config/env/aws_credentials.env | /.vscode/launch.json | /.ssh/id_ed25519 | /.ssh/id_rsa. UTC: 2026-09-06 09:34:28.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 10:06:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.143.165.69 (69.165.143.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.165.69 (69.165.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:06:53.753285 2026] [security2:error] [pid 18044:tid 18044] [client 34.143.165.69:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbproductionsonline.com"] [uri "/.env.bak"] [unique_id "ap07PaZYHhKYl0dLrqFm8QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Halux
2026-09-06 09:58:52
(5 hours ago)
34.143.165.69 Web Application Firewall multiple violations
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-06 09:55:15
(5 hours ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-06 09:51:04
(5 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
🇩🇪
Gwyneth Llewelyn
2026-09-06 09:21:24
(6 hours ago)
2026/09/06 10:21:20 [error] 380594#380594: *3198226 access forbidden by rule, client: 34.143.165.69, ...
show more
2026/09/06 10:21:20 [error] 380594#380594: *3198226 access forbidden by rule, client: 34.143.165.69, server: mar.pt, request: "GET /public../.env HTTP/2.0", host: "mar.pt", referrer: "https://www.mar.pt/public../.env"
2026/09/06 10:21:21 [error] 380594#380594: *3198226 access forbidden by rule, client: 34.143.165.69, server: mar.pt, request: "GET /build../.env HTTP/2.0", host: "mar.pt", referrer: "https://www.mar.pt/build../.env"
2026/09/06 10:21:21 [error] 380594#380594: *3198226 access forbidden by rule, client: 34.143.165.69, server: mar.pt, request: "GET /dist../.env HTTP/2.0", host: "mar.pt", referrer: "https://www.mar.pt/dist../.env"
show less
Brute-Force
Web App Attack