🇨🇦
Webmestre
2026-09-07 12:12:00
(9 hours ago)
Attempts against non-existent WordPress and PHP pages /backend/.env, /wp-content/.env /Admin/phpinfo ...
show more
Attempts against non-existent WordPress and PHP pages /backend/.env, /wp-content/.env /Admin/phpinfo.php
show less
Bad Web Bot
Web App Attack
Hacking
Anonymous
2026-09-07 04:15:22
(17 hours ago)
34.148.178.71 - - [06/Sep/2026:12:42:38 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
34.148.178.71 - - [06/Sep/2026:12:42:38 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 34.148.178.71
34.148.178.71 - - [06/Sep/2026:12:42:38 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 34.148.178.71
34.148.178.71 - - [06/Sep/2026:12:42:38 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 34.148.178.71
34.148.178.71 - - [06/Sep/2026:12:42:38 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)" 34.148.178.71
34.148.178.71 - - [06/Sep/2026:12:42:38 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https:/
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 03:05:37
(18 hours ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-07 01:47:33
(19 hours ago)
Excessive multi-domain requests
Brute-Force
🇷🇴
clauss
2026-09-07 01:17:29
(20 hours ago)
34.148.178.71 - - [07/Sep/2026:04:17:25 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///ro ...
show more
34.148.178.71 - - [07/Sep/2026:04:17:25 +0300] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/2.0" 404 14160 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
34.148.178.71 - - [07/Sep/2026:04:17:28 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Web App Attack
Anonymous
2026-09-07 01:01:07
(20 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:45:56
(23 hours ago)
(mod_security) mod_security (id:210580) triggered by 34.148.178.71 (71.178.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 34.148.178.71 (71.178.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:45:50.957912 2026] [security2:error] [pid 26748:tid 26748] [client 34.148.178.71:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||tellusafe.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "tellusafe.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap3fDnGe6bwW78gG_jX5iAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 18:00:25
(1 day ago)
SecLists/Directory Fuzzing Scanner. Automated Subnet Quarantine.
Port Scan
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 16:58:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.178.71 (71.178.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.178.71 (71.178.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:58:01.645634 2026] [security2:error] [pid 22881:tid 22881] [client 34.148.178.71:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perl-photo.com"] [uri "/.github/.env"] [unique_id "ap2bmQF9EXXoFdGHbf83HAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:59:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.178.71 (71.178.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.178.71 (71.178.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:59:31.821202 2026] [security2:error] [pid 13667:tid 13667] [client 34.148.178.71:54370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ondakompun.com"] [uri "/.htpasswd"] [unique_id "ap2N45H6btxcpf5bkiVsKgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 15:58:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-06 17:53:56,879 fail2ban.filter [2048]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-06 17:53:56,879 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 49.42.64.53 - 2026-09-06 17:53:56cloudlinux2 fail2ban: 2026-09-06 17:54:08,104 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.187.168.18 - 2026-09-06 17:54:07cloudlinux2 fail2ban: 2026-09-06 17:54:09,257 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.187.168.18 - 2026-09-06 17:54:09cloudlinux2 fail2ban: 2026-09-06 17:54:18,992 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 49.42.64.53 - 2026-09-06 17:54:18cloudlinux2 fail2ban: 2026-09-06 17:54:19,773 fail2ban.filter [2048]: INFO [recidive] Found 49.42.64.53 - 2026-09-06 17:54:19cloudlinux2 fail2ban: 2026-09-06 17:54:19,767 fail2ban.actions [2048]: NOTICE [plesk-modsecurity] Ban 49.42.64.53cloudlinux2 fail2ban: 2026-09-06 17:55:18,311 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 136.67.56.79 - 2026-09-06 17:55:18cloudlinux2 fail2ban: 2026-09-06 17:5
show less
Brute-Force
🇫🇷
dynamix
2026-09-06 14:42:28
(1 day ago)
Multiple WAF Violations
Web App Attack
🇫🇮
as211431.net
2026-09-06 14:24:29
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.env.docker
UA: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-06 14:07:01
(1 day ago)
Attempting to access restricted files
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:49:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.178.71 (71.178.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.178.71 (71.178.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:49:37.690945 2026] [security2:error] [pid 22492:tid 22492] [client 34.148.178.71:37770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.petersonzeyerlaw.com"] [uri "/@fs/../.env"] [unique_id "ap1vcQcbXXaRQbOp7WHEUwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack