π«π·
SpaceHost-Server
2026-09-01 22:22:32
(8 hours ago)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 13:49:45
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:49:40.912278 2026] [security2:error] [pid 1624:tid 1687] [client 34.89.243.48:46030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.southtampaprints.com"] [uri "/wp-config.php~"] [unique_id "apbX9FRblctnz_ngpDMPfgAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πΎ
lns.bz
2026-09-01 12:53:21
(18 hours ago)
.env scanning [BY]
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:27:02
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:26:54.939383 2026] [security2:error] [pid 20081:tid 20102] [client 34.89.243.48:44314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cargowebstore.newleafpro.com"] [uri "/.env.local"] [unique_id "apbEjlTFwdOKcQJZPCRW_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SCHAPPY
2026-09-01 09:59:12
(20 hours ago)
Mutliple attempts to access forbidden web resources, HTTP code 403.
Web App Attack
π«π·
mrcrassi
2026-09-01 09:33:57
(21 hours ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.bak
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-01 09:26:54
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:26:46.250904 2026] [security2:error] [pid 29328:tid 29605] [client 34.89.243.48:36684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coasterdvdsonline.com"] [uri "/.env.dev"] [unique_id "apaaVvNt_sk3ZJBCFgxgFQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
r4fo.com
2026-09-01 08:51:02
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 08:46:28
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.243.48 (48.243.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:46:23.935145 2026] [security2:error] [pid 11745:tid 11745] [client 34.89.243.48:41642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serpentstudios.com"] [uri "/.env"] [unique_id "apaQ3_rjZN9-iNHMQxMvjwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
dispensight
2026-09-01 08:01:42
(22 hours ago)
Credential/config file harvesting. 19 request(s) against s01-app.dispensight.ca between 2026-09-01 0 ...
show more
Credential/config file harvesting. 19 request(s) against s01-app.dispensight.ca between 2026-09-01 01:01 and 2026-09-01 01:01 (America/Vancouver). Sample paths: /.env.backup; /.env.bak; /.env.prod. Observed on origin web logs + tunnel telemetry. Automated detection, manually reviewed. Reported by Dispensight/SecureLeaf.
show less
Web App Attack
Hacking
π©πͺ
LRob
2026-09-01 07:44:27
(23 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+12 more) | 2026-09-01 07:44 UTC
show less
Hacking
Web App Attack
π©πͺ
todix
2026-09-01 06:43:40
(1 day ago)
Web App Attack Exploid from 34.89.243.48
Web App Attack
π©πͺ
raph
2026-09-01 04:20:44
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
πΈπ¬
Shubham Kumar
2026-09-01 03:42:38
(1 day ago)
Repeated scrape-guard abuse (flag #0)
Web App Attack
π¨π¦
Anytech
2026-09-01 03:42:05
(1 day ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking