🇺🇸
TPI-Abuse
2026-09-06 03:51:46
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:51:42.650631 2026] [security2:error] [pid 15969:tid 15989] [client 34.39.179.20:42040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.birdhousefarms.com"] [uri "/wp-config.php~"] [unique_id "apzjTp6NkPE_6xMYHKO_3wAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
zXero
2026-09-06 03:37:48
(58 minutes ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
🇺🇸
TPI-Abuse
2026-09-06 03:35:40
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:35:36.607775 2026] [security2:error] [pid 9331:tid 9331] [client 34.39.179.20:59456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "piments.com"] [uri "/.env.backup"] [unique_id "apzfiJh8kX3UiX1gp3YVNQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 02:53:44
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 02:46:00
(1 hour ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:10:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:10:19.739797 2026] [security2:error] [pid 20770:tid 20770] [client 34.39.179.20:49006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.marijuanajoint.com"] [uri "/.env.save"] [unique_id "apy9e33ZD94nNTwt-cd7PwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(4 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
4server
2026-09-06 00:01:21
(4 hours ago)
[SunSep0602:01:18.9981912026][security2:error][pid2183286:tid2183381][client34.39.179.20:0]ModSecuri ...
show more
[SunSep0602:01:18.9981912026][security2:error][pid2183286:tid2183381][client34.39.179.20:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"kiteinvest.ch\"][uri\"/.env.dev\"][unique_id\"apytTq0Nu4bQc7yxsF5sQAAAAI4\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:00:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:00:04.969834 2026] [security2:error] [pid 11646:tid 11699] [client 34.39.179.20:54902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kamins.org"] [uri "/.env.production"] [unique_id "apytBMhY564o5wKLIwiw9wAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:27:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:27:31.552169 2026] [security2:error] [pid 13128:tid 13128] [client 34.39.179.20:52712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jinkokyudojo.com"] [uri "/wp-config.php~"] [unique_id "apylY1gihRQamvad0fiQfAAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 23:00:42
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇫🇷
mrcrassi
2026-09-05 21:41:51
(6 hours ago)
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php~
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 14:46:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:46:31.968287 2026] [security2:error] [pid 22878:tid 22878] [client 34.39.179.20:50718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carminestogo.com"] [uri "/.env.save"] [unique_id "aprZx543E8W-WekMMSG7mwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.179.20 (20.179.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:54.180229 2026] [security2:error] [pid 810774:tid 810774] [client 34.39.179.20:34924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.arogun.org"] [uri "/.env.save"] [unique_id "aprQuprOjbTd7f8wT63fBQAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 13:25:19
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack