🇳🇱
tmiland
2026-09-06 06:21:26
(25 minutes ago)
(nginx_404) Dot directory Honeypot Trap 34.39.141.239 (BR/Brazil/239.141.39.34.bc.googleusercontent. ...
show more
(nginx_404) Dot directory Honeypot Trap 34.39.141.239 (BR/Brazil/239.141.39.34.bc.googleusercontent.com): 2 in the last 3600 secs; IP: 34.39.141.239; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.39.141.239 - - [06/Sep/2026:08:21:22 +0200] "GET /.env.dev HTTP/1.1" 404 2992 "-" "crusader-worker/1.0" 34.39.141.239 - - [06/Sep/2026:08:21:22 +0200] "GET /.env.old HTTP/1.1" 404 2992 "-" "crusader-worker/1.0"
show less
Brute-Force
🇺🇦
URAN Publishing Service
2026-09-06 02:56:13
(3 hours ago)
[06/Sep/2026:05:56:12 +0300] -- 34.39.141.239 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[06/Sep/2026:05:56:12 +0300] -- 34.39.141.239 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.swp HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:45:55
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:45:50.249954 2026] [security2:error] [pid 32446:tid 32446] [client 34.39.141.239:48220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.moonstonenightclub.com"] [uri "/.env.save"] [unique_id "apzFzuk22ptc06Ax-T59gwAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 01:35:22
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇴
jad-abuse
2026-09-06 01:32:27
(5 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: actuator, ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: actuator, scanner_ua, env_probe, source_backup, config_backup, ignition_debug. Observed by 1 sensor(s); 19 hits.
show less
Hacking
Web App Attack
Anonymous
2026-09-06 00:57:29
(5 hours ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.esperohotel.gr; logs=/var/log/httpd/domains/esperohotel. ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.esperohotel.gr; logs=/var/log/httpd/domains/esperohotel.gr.log; samples=/.env.old | /.env.backup | /.env.save
show less
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-06 00:33:33
(6 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:58:23
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:58:15.994763 2026] [security2:error] [pid 14350:tid 14350] [client 34.39.141.239:53226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jmichaelpope.com"] [uri "/.env.prod"] [unique_id "apysl8GEFbMINNn800XnaQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:55:02
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:54:54.284004 2026] [security2:error] [pid 28768:tid 28768] [client 34.39.141.239:41202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eworld-media.com"] [uri "/.env"] [unique_id "apydvgWwm79SbgIek0oBegAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:21:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:21:14.680722 2026] [security2:error] [pid 24214:tid 24214] [client 34.39.141.239:43654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bencramerinc.com"] [uri "/.htaccess"] [unique_id "apyV2mE4OADqyYMTto6ymAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
GabrielJST
2026-09-05 21:54:53
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.39.141.239 (BR/Brazil/239.141.39.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.39.141.239 (BR/Brazil/239.141.39.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇫🇮
as211431.net
2026-09-05 21:44:14
(9 hours ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env/
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-05 21:34:36
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:34:29.100689 2026] [security2:error] [pid 4899:tid 4899] [client 34.39.141.239:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.globetechsecurities.com"] [uri "/.env.prod"] [unique_id "apyK5YR9kqKR4RKGaHmmUwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:01:07
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.141.239 (239.141.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:01:00.446576 2026] [security2:error] [pid 30836:tid 30836] [client 34.39.141.239:55512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amrtactical.com"] [uri "/wp-config.php.bak"] [unique_id "apyDDBkcoheiHeiqddv2JAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 20:41:43
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack