Anonymous
2026-09-07 10:43:30
(7 hours ago)
Web scanner: GET /@fs/.env.development?raw??
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-07 10:17:37
(8 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 10:05:17
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:05:12.049362 2026] [security2:error] [pid 9236:tid 9236] [client 35.232.217.221:9510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jewersmail.com"] [uri "/@fs/root/.env"] [unique_id "ap6MWC1-Y4rr4Eyg-B-k9AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-07 09:14:05
(9 hours ago)
Try to access /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??
Web App Attack
🇺🇸
antlac1
2026-09-07 09:11:11
(9 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-07 08:31:36
(9 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
IndigoRidge
2026-09-07 08:23:20
(9 hours ago)
[07/Sep/2026:04:23:20.311826 --0400] ap50eJOb1TZn2PAf0uw9GQAAAs4 35.232.217.221 46628 205.233.18.17 ...
show more
[07/Sep/2026:04:23:20.311826 --0400] ap50eJOb1TZn2PAf0uw9GQAAAs4 35.232.217.221 46628 205.233.18.17 7080
[07/Sep/2026:04:23:20.349879 --0400] ap50eIt2UKva1HT0ESbkyQAAAoY 35.232.217.221 46654 205.233.18.17 7080
[07/Sep/2026:04:23:20.350315 --0400] ap50eIt2UKva1HT0ESbkygAAAoY 35.232.217.221 46666 205.233.18.17 7080
[07/Sep/2026:04:23:20.350787 --0400] ap50eIt2UKva1HT0ESbkywAAAoY 35.232.217.221 46682 205.233.18.17 7080
[07/Sep/2026:04:23:20.354318 --0400] ap50eIt2UKva1HT0ESbkzQAAAoQ 35.232.217.221 46720 205.233.18.17 7080
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-07 08:16:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:16:12.276762 2026] [security2:error] [pid 21052:tid 21052] [client 35.232.217.221:1924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.leannadsweeney.com"] [uri "/@fs/.env"] [unique_id "ap5yzHPLWIVkiD-GwbJhWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-07 08:13:30
(10 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /root/.aws/config
UA: Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4070.238 Safari/537.36; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
iNetWorker
2026-09-07 08:09:29
(10 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-07 07:44:46
(10 hours ago)
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked.. Matched phrase "Bytespider" at REQUEST_H ...
show more
BAD BOT, BAD BOT, WHAT YA GONNA DO - Detected and Blocked.. Matched phrase "Bytespider" at REQUEST_HEADERS:User-Agent. (1100000-mnz6-1)
show less
Bad Web Bot
🇧🇪
cmbplf
2026-09-07 07:39:51
(10 hours ago)
2.978 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 07:35:52
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:35:46.004818 2026] [security2:error] [pid 13403:tid 13403] [client 35.232.217.221:35552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4ehardware.4ehardware.com"] [uri "/@fs/.env"] [unique_id "ap5pUiH1vd6CkmUv2kyleAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:10:48
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:10:42.796163 2026] [security2:error] [pid 28005:tid 28005] [client 35.232.217.221:7598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "duckchristmascards.com"] [uri "/@fs/.env.production"] [unique_id "ap5jcvhhTjnRyTiofhoeCgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:54:41
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.217.221 (221.217.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:54:37.891202 2026] [security2:error] [pid 5407:tid 5407] [client 35.232.217.221:15714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.northernfrontier.net"] [uri "/@fs/.env.development"] [unique_id "ap5frfbWa-PYZQBdvBa0SQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack