๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:03:45
(25 minutes ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 21:59:48
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐ฌ๐ง
pinguin
2026-09-22 16:06:58
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
sigurg
2026-09-22 15:53:48
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 15:39:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:39:46.218257 2026] [security2:error] [pid 16397:tid 16397] [client 35.194.84.177:35622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "normsrotorservice.com"] [uri "/.env.old"] [unique_id "arKhQlzjzO9D0e_vBtqfogAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 15:06:00
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:29:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:29:44.535554 2026] [security2:error] [pid 11607:tid 11616] [client 35.194.84.177:39176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lesleyhcampbell.com"] [uri "/.env"] [unique_id "arKQ2CO2a1zmYD5JgUY2ogAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-22 13:58:32
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.194.84.177 (US/United States/177.84. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.194.84.177 (US/United States/177.84.194.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 13:57:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:57:25.954743 2026] [security2:error] [pid 26305:tid 26305] [client 35.194.84.177:38672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inlinesoftware.net"] [uri "/.env.production"] [unique_id "arKJRV7E9fu9fLA4qK-cVAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 13:55:18
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 13:42:54
(1 day ago)
[ti-hoogstraov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Exampl ...
show more
[ti-hoogstraov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.194.84.177 - - \[22/Sep/2026:15:42:46 +0200\] "GET /wp-config.php.bak HTTP/1.1" 403 6176 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 13:40:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-22 13:32:09
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:30:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.84.177 (177.84.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:30:35.498362 2026] [security2:error] [pid 28882:tid 28882] [client 35.194.84.177:59994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graydortmotors.com"] [uri "/.env.save"] [unique_id "arKC-9oggCYRiva66IBV8AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-22 12:15:04
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack