🇳🇱
homeshowdomain.nl
2026-09-05 22:00:40
(59 minutes ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇬🇧
consul.to
2026-09-05 20:58:09
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇬🇧
blueskysystems
2026-09-05 10:30:02
(12 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇮🇩
PENJAGA.AUM
2026-09-05 08:56:41
(14 hours ago)
34.68.67.219 - Attack: ET WEB_SERVER Tilde in URI - potential .php~ source disclosure vulnerability
Web App Attack
SQL Injection
Spoofing
🇺🇸
etu brutus
2026-09-05 07:32:42
(15 hours ago)
34.68.67.219 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
Anonymous
2026-09-05 07:06:41
(15 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:17:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:17:28.944787 2026] [security2:error] [pid 6558:tid 6558] [client 34.68.67.219:33982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.nextngnr.com"] [uri "/.env.bak"] [unique_id "aprhCJaaRyhSeq2jrOjEcAAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:10:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:10:28.873559 2026] [security2:error] [pid 4355:tid 4363] [client 34.68.67.219:53408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wasula.com"] [uri "/.env.production"] [unique_id "aprRVMKZoYaNsgIbwhvA_gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
pinguin
2026-09-04 13:42:22
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env/
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
pscriptos
2026-09-04 12:36:42
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 12:32:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:32:42.333691 2026] [security2:error] [pid 11162:tid 11162] [client 34.68.67.219:43212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gdijoe.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gdijoe.com"] [uri "/storage/logs/laravel.log"] [unique_id "apq6as9AypFk--B2r-CGZAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 12:05:36
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
🇲🇾
Rizzy
2026-09-04 12:02:21
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇩🇪
raph
2026-09-04 11:47:10
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:45:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.68.67.219 (219.67.68.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:45:21.881995 2026] [security2:error] [pid 5103:tid 5103] [client 34.68.67.219:53278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fatcaverecords.com"] [uri "/.env"] [unique_id "apqvUXZohxBE_x9pUYz8yAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack