Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=44; exact paths: /.env | /.env.backup | /.env.bak | /.env.development.local | ...
show more
Apache probe; attempts=44; exact paths: /.env | /.env.backup | /.env.bak | /.env.development.local | /.env.dist | /.env.local | /.env.old | /.env.production | /.env.production.local | /.env.sample | /.env.save | /.env.test | /.git/HEAD | /.git/config
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-24 06:00:00
(6 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-07-23 16:31:43
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-23 14:25:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 10:25:50.935915 2026] [security2:error] [pid 3109430:tid 3109430] [client 34.87.144.238:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.manueltoren.com.dandemonium.net"] [uri "/.env.local"] [unique_id "amIkbl8qQKJ5SAoBozFklgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-23 13:32:20
(1 week ago)
[ThuJul2315:32:16.6188162026][security2:error][pid3112613:tid3112892][client34.87.144.238:0]ModSecur ...
show more
[ThuJul2315:32:16.6188162026][security2:error][pid3112613:tid3112892][client34.87.144.238:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\"wp-config\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"duoacaja.com\"][uri\"/wp-config.php\"][unique_id\"amIX4PL0wxTC0yuOZOwBRgAAAUQ\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 13:14:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 09:14:42.757329 2026] [security2:error] [pid 2165465:tid 2165465] [client 34.87.144.238:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evolinc.com"] [uri "/.git/HEAD"] [unique_id "amITwvLgWjX9qtwQm2ZtzAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-07-23 12:34:27
(1 week ago)
F2B - Malicious activity detected. URL Probing. -c23856ef-
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-23 12:08:43
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (HEAD met ...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /wp-config.php
UA: Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
Klaverstyn
2026-07-23 11:51:18
(1 week ago)
Repeated 403 Forbidden responses
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 11:25:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 07:25:20.042300 2026] [security2:error] [pid 2528946:tid 2528946] [client 34.87.144.238:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antitribu.com"] [uri "/.env.local"] [unique_id "amH6IK8f9-DqhcXH6VqH9gAAAAg"], referer: https://www.google.com/search?q=antitribu.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-23 10:41:57
(1 week ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.local
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 10:20:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 06:19:51.393208 2026] [security2:error] [pid 402310:tid 402310] [client 34.87.144.238:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ted.krakowski.org"] [uri "/.git/config"] [unique_id "amHqxwvP5R1ldKl4vjny0wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-07-23 09:52:19
(1 week ago)
tcp/443 (2 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-23 09:15:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.144.238 (238.144.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:15:39.549393 2026] [security2:error] [pid 3649365:tid 3649365] [client 34.87.144.238:34448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "halleycpa.com"] [uri "/.env"] [unique_id "amHbu5TaHhobqJyUnIhCaQAAABA"], referer: https://www.google.com/search?q=halleycpa.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SwinT
2026-07-23 09:00:05
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack