🇺🇸
wteiken
2026-08-29 03:06:10
(12 hours ago)
2026-08-28T23:06:08.157490-04:00 rocinante.teiken.net kernel: [215469.324020] syn_limit:IN=ens5 OUT= ...
show more
2026-08-28T23:06:08.157490-04:00 rocinante.teiken.net kernel: [215469.324020] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=35.237.19.63 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=47383 DF PROTO=TCP SPT=52272 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-28T23:06:08.167586-04:00 rocinante.teiken.net kernel: [215469.326693] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=35.237.19.63 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=27066 DF PROTO=TCP SPT=52288 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-28T23:06:08.167648-04:00 rocinante.teiken.net kernel: [215469.329367] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=35.237.19.63 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=61414 DF PROTO=TCP SPT=52296 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-28T23:06:08.167723-04:00 rocinante.teiken.net kernel: [215469.332060] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:a
...
show less
Port Scan
🇳🇱
debestelapp
2026-08-29 02:55:09
(12 hours ago)
Web App Attack
🇺🇸
MPL
2026-08-29 02:47:48
(13 hours ago)
tcp ports: 80,443 (76 or more attempts)
Port Scan
🇺🇸
TPI-Abuse
2026-08-29 02:14:09
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:14:05.717251 2026] [security2:error] [pid 87682:tid 87699] [client 35.237.19.63:55692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fconct.pwrcoupling.com"] [uri "/wp-config.php.swp"] [unique_id "apJAbYGTbCiobpHld9phqAAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:36:54
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:36:50.873983 2026] [security2:error] [pid 6487:tid 6487] [client 35.237.19.63:36392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clubfansite.com"] [uri "/.env.save"] [unique_id "apI3slyCWrSAuWb7YHJ9cgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-08-29 01:17:08
(14 hours ago)
Domain : test.communique.co.za
Rule : env
2026-08-29 01:14:13 ***hidden-privacy*** GET /.env - 80 - ...
show more
Domain : test.communique.co.za
Rule : env
2026-08-29 01:14:13 ***hidden-privacy*** GET /.env - 80 - 35.237.19.63 HTTP/1.1 crusader-worker/1.0 - test.communique.co.za 403 0 0 1497 97 815 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-08-29 01:06:42
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:06:38.683476 2026] [security2:error] [pid 9342:tid 9342] [client 35.237.19.63:50966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.desertshadowsrv.org"] [uri "/.env.save"] [unique_id "apIwnqvYTCVOP3wArbd_WQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-08-28 23:00:05
(16 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 21:59:11
(17 hours ago)
Auto-ban: >3000 req/min op 2026-08-28
Web App Attack
SSH
Hacking
Anonymous
2026-08-28 21:31:02
(18 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /storage/logs/laravel.log HTTP/1 ...
show more
Bot / scanning and/or hacking attempts: GET /.env.old HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.production HTTP/1.1, GET /actuator/env HTTP/1.1, GET /.env HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.dev HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.prod HTTP/1.1, GET /env HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 19:40:35
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:40:29.806708 2026] [security2:error] [pid 29905:tid 29905] [client 35.237.19.63:39190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.marcosmelero.com"] [uri "/wp-config.php.bak"] [unique_id "apHkLXcaFI3CsGefl6RLuAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
webanyone
2026-08-28 19:32:06
(20 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇫🇮
as211431.net
2026-08-28 18:45:37
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //.env
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-28 17:44:15
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.19.63 (63.19.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:44:11.135580 2026] [security2:error] [pid 17358:tid 17358] [client 35.237.19.63:47420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thainotarycalifornia.com"] [uri "/.env.dev"] [unique_id "apHI61pOuMt6JmIFT01wcwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-08-28 16:48:45
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking