πΊπΈ
robotstxt
2026-09-18 09:12:05
(3 weeks ago)
34.18.85.246 - - [18/Sep/2026:09:11:04 +0000] "GET /.env HTTP/1.1" 403 17847 "-" "Mozilla/5.0 (Windo ...
show more
34.18.85.246 - - [18/Sep/2026:09:11:04 +0000] "GET /.env HTTP/1.1" 403 17847 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:09:11:04 +0000] "GET /.env.local HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:09:11:04 +0000] "GET /.env.production HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:09:11:05 +0000] "GET /.env.staging HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:09:11:05 +0000] "GET /.env.development HTTP/1.1" 403 17842 "-" "Mozil
...
show less
Web App Attack
π¦πΊ
rubixstudios
2026-09-18 08:43:02
(3 weeks ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
πΊπΈ
robotstxt
2026-09-18 07:27:42
(3 weeks ago)
34.18.85.246 - - [18/Sep/2026:07:26:41 +0000] "GET /.env HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (X11; ...
show more
34.18.85.246 - - [18/Sep/2026:07:26:41 +0000] "GET /.env HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:07:26:41 +0000] "GET /.env.local HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:07:26:41 +0000] "GET /.env.production HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:07:26:42 +0000] "GET /.env.staging HTTP/1.1" 403 17847 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.18.85.246"
34.18.85.246 - - [18/Sep/2026:07:26:42 +0000] "GET /.env.development HTTP/1.1" 403 17842 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/5
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 07:19:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:19:31.624536 2026] [security2:error] [pid 23060:tid 23114] [client 34.18.85.246:43228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalattorney.biz"] [uri "/.git/config"] [unique_id "aqzmA-sx56lN8PbxNTlTwAAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-18 06:31:41
(3 weeks ago)
[18/Sep/2026:09:31:41 +0300] -- 34.18.85.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[18/Sep/2026:09:31:41 +0300] -- 34.18.85.246 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2026-09-18 05:56:27
(3 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from QA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from QA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-17 04:17:02
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:16:55.287705 2026] [security2:error] [pid 8244:tid 8244] [client 34.18.85.246:46446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modalsoftware.com"] [uri "/.git/config"] [unique_id "aqtpt918fP6hginH4bTpMwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
middelkoopcc
2026-09-17 04:15:02
(3 weeks ago)
2026-09-17 06:13:10 GET /.git/config [301] && 2026-09-17 06:13:10 GET /.env [301] && 2026-09-17 06:1 ...
show more
2026-09-17 06:13:10 GET /.git/config [301] && 2026-09-17 06:13:10 GET /.env [301] && 2026-09-17 06:13:11 GET /.env.bak [301] && 239 more within 20 minutes
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 02:35:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:35:36.809251 2026] [security2:error] [pid 28873:tid 28873] [client 34.18.85.246:37602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobiletitleclerk.com"] [uri "/.git/config"] [unique_id "aqtR-OO8xRbdSqawTxmpCQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
zynex
2026-09-17 02:18:14
(3 weeks ago)
URL Probing: /server/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 02:10:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:10:44.393752 2026] [security2:error] [pid 5688:tid 5688] [client 34.18.85.246:34022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mobileonlinecasinos.co"] [uri "/.git/config"] [unique_id "aqtMJJ67Xg2fTOLZ6KjdSAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 02:19:58
(3 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
π³π±
Site.eu
2026-09-16 01:14:36
(3 weeks ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-16 01:03:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.85.246 (246.85.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:03:02.406271 2026] [security2:error] [pid 22578:tid 22578] [client 34.18.85.246:39316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inspiringindividualindustry.com"] [uri "/.git/config"] [unique_id "aqnqxmJ3XJlbEPWgsWaIGwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
COMAITE
2026-09-16 00:46:26
(3 weeks ago)
Suspicious URL access.
Web App Attack