🇺🇸
infra-monitor
2026-09-09 03:00:06
(1 hour ago)
Automated ban via infra-monitor: suspicious-probe
Port Scan
🇬🇧
pinguin
2026-09-09 01:24:49
(3 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /core/.env
UA: python-requests/2.34.2
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
lolyay
2026-09-09 01:12:35
(3 hours ago)
34.26.170.169 - - [09/Sep/2026:01:12:34 +0000] "GET /.env HTTP/1.1" 200 4 "-" "python-requests/2.34. ...
show more
34.26.170.169 - - [09/Sep/2026:01:12:34 +0000] "GET /.env HTTP/1.1" 200 4 "-" "python-requests/2.34.2"
34.26.170.169 - - [09/Sep/2026:01:12:34 +0000] "GET /.env HTTP/1.1" 200 4 "-" "python-requests/2.34.2"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 01:03:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:02:56.641254 2026] [security2:error] [pid 12286:tid 12286] [client 34.26.170.169:58200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "listings.cruisingforsex.com"] [uri "/.env"] [unique_id "aqCwQD-_N94-Vuq72HYqxgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 01:00:11
(3 hours ago)
Unauthorized SSH login attempts
Brute-Force
SSH
🇨🇭
blinx
2026-09-09 00:47:39
(3 hours ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:44:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:44:47.458958 2026] [security2:error] [pid 30883:tid 30883] [client 34.26.170.169:61622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bwill.dev"] [uri "/.env"] [unique_id "aqCr_6cDTRGDbzF0adIHiwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bryth
2026-09-09 00:44:27
(3 hours ago)
Wordpress login/xmlrpc abuse (Wed Sep 9 12:26:46 AM UTC 2026)
Hacking
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-09 00:38:18
(4 hours ago)
[09/Sep/2026:03:38:17 +0300] -- 34.26.170.169 Ban reason: User-Agent python-requests
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-09-09 00:36:17
(4 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:00:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:00:25.538494 2026] [security2:error] [pid 18467:tid 18467] [client 34.26.170.169:56966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garanta.co"] [uri "/.env"] [unique_id "aqChmWRAWFLJrxzVlw4kngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
ELYAZ
2026-09-08 23:56:54
(4 hours ago)
(y3) Failed access -byebye- from 34.26.170.169 (US/United States/169.170.26.34.bc.googleusercontent. ...
show more
(y3) Failed access -byebye- from 34.26.170.169 (US/United States/169.170.26.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇬🇧
Bytemark
2026-09-08 23:55:09
(4 hours ago)
34.26.170.169 - - [09/Sep/2026:00:55:08 +0100] "GET /.env HTTP/1.1" 301 6752 "-" "python-requests/2. ...
show more
34.26.170.169 - - [09/Sep/2026:00:55:08 +0100] "GET /.env HTTP/1.1" 301 6752 "-" "python-requests/2.34.2"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-08 23:49:23
(4 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:45:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.170.169 (169.170.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:45:11.308910 2026] [security2:error] [pid 22422:tid 22422] [client 34.26.170.169:56946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arabou.co"] [uri "/.env"] [unique_id "aqCeB8mhaogGqArY3Glf5AAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack