🇩🇪
paissangroup
2026-09-04 14:44:58
(1 day ago)
Multiple WAF Violations
Web App Attack
🇩🇪
dbmwebdesign
2026-09-04 14:40:07
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:11:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:11:04.736274 2026] [security2:error] [pid 8297:tid 8341] [client 34.65.222.131:39070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.maroontribe.com"] [uri "/wp-config.php~"] [unique_id "aprReFF0V6dcAmwFugfdwgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:02:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:01:59.306166 2026] [security2:error] [pid 26549:tid 26549] [client 34.65.222.131:54058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "servecon.net.herston.net"] [uri "/.env.production"] [unique_id "aprBR0Z5a67H1QsY1gOUqgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 12:38:39
(1 day ago)
[04/Sep/2026:15:38:38 +0300] -- 34.65.222.131 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-c ...
show more
[04/Sep/2026:15:38:38 +0300] -- 34.65.222.131 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-config.php.swp HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:16:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:16:11.273157 2026] [security2:error] [pid 12533:tid 12533] [client 34.65.222.131:34090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moonstonenightclub.com"] [uri "/.env.old"] [unique_id "apq2i9LHCtCbC-BEs3hTcAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Stara
2026-09-04 11:46:38
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 10:15:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:00:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:00:02.618986 2026] [security2:error] [pid 5437:tid 5437] [client 34.65.222.131:48600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jerryhazlett.com"] [uri "/.env.example"] [unique_id "apqWokqP7uz4Rjfi-aXmuwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Webhoster
2026-09-04 09:57:05
(1 day ago)
CrowdSec detected crowdsecurity/http-sensitive-files on a monitored service.
Web App Attack
Anonymous
2026-09-04 09:20:27
(1 day ago)
Scanner hitting /.env.save on livekit.osef.cloud (GOOGL-2) — aaguard
Brute-Force
Port Scan
🇬🇧
pinguin
2026-09-04 08:41:59
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from CH.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CH.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 08:26:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:26:10.293207 2026] [security2:error] [pid 3530:tid 3530] [client 34.65.222.131:41706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.starcrestsales.com"] [uri "/wp-config.php.bak"] [unique_id "apqAoqW5TxsR5ptnAQgfLAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
i-turnradio.nl
2026-09-04 08:04:26
(1 day ago)
2026-09-04 @ 10:04:26 (CET) ~ Blocked for trying to access: /wp-config.php.bak
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:48:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.222.131 (131.222.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:48:25.896974 2026] [security2:error] [pid 4691:tid 4800] [client 34.65.222.131:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.mindgardens.com"] [uri "/.env"] [unique_id "app3yYZiW6PqWYUwGvUPNgAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack