🇫🇷
SpaceHost-Server
2026-09-04 22:19:54
(1 day ago)
Brute-Force
Web App Attack
🇪🇸
Gem
2026-09-04 22:11:47
(1 day ago)
Unauthorized web scan.
Web App Attack
🇫🇮
as211431.net
2026-09-04 15:00:21
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-04 14:45:03
(1 day ago)
suspicious request in access.log
Web App Attack
🇳🇱
e.fierstra
2026-09-04 14:40:36
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:15:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:15:38.935243 2026] [security2:error] [pid 3741:tid 3741] [client 34.181.242.173:47826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.toyz.net"] [uri "/.env"] [unique_id "aprSir7OTq7GOeS7SX8WqAAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 14:10:26
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇦🇺
2000cn.com.au
2026-09-04 13:24:33
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
pltcldvlpr
2026-09-04 12:56:27
(1 day ago)
CMS/framework probe: 34.181.242.173 - - [04/Sep/2026:14:56:27 +0200] "GET /.env.backup HTTP/1.1" 444 ...
show more
CMS/framework probe: 34.181.242.173 - - [04/Sep/2026:14:56:27 +0200] "GET /.env.backup HTTP/1.1" 444 0 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:55:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:55:46.762811 2026] [security2:error] [pid 16462:tid 16462] [client 34.181.242.173:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "map.365soft.top"] [uri "/.env.prod"] [unique_id "apq_0peJIV5be4rSsWOk5wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
itsolon
2026-09-04 11:48:54
(1 day ago)
[04/Sep/2026:13:48:54 +0200] 178852253482.621515 34.181.242.173 38662 217.154.7.177 443
[04/Sep/2026 ...
show more
[04/Sep/2026:13:48:54 +0200] 178852253482.621515 34.181.242.173 38662 217.154.7.177 443
[04/Sep/2026:13:48:54 +0200] 17885225341.361810 34.181.242.173 38660 217.154.7.177 443
[04/Sep/2026:13:48:54 +0200] 17885225346.698671 34.181.242.173 38624 217.154.7.177 443
[04/Sep/2026:13:48:54 +0200] 178852253428.377566 34.181.242.173 38656 217.154.7.177 443
[04/Sep/2026:13:48:54 +0200] 178852253473.413895 34.181.242.173 38676 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-04 11:47:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /wp-config.php~ HT ...
show more
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /wp-config.php~ HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.backup HTTP/1.1, GET /actuator/configprops HTTP/1.1, GET /.env.local HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /env HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:25:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:25:31.282010 2026] [security2:error] [pid 20715:tid 20998] [client 34.181.242.173:48918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ethniclivesmatter.com"] [uri "/.env.bak"] [unique_id "apqqqxKoCyJEX5z1mHPsvQAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:21:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.242.173 (173.242.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:21:42.111005 2026] [security2:error] [pid 3598:tid 3598] [client 34.181.242.173:43402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "odinathletes.com"] [uri "/wp-config.php~"] [unique_id "apqbthNIIGUiTuRAlt9FTQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-04 10:02:59
(1 day ago)
Suspicious URL access.
Web App Attack