🇳🇱
Alt255
2026-09-15 15:18:56
(5 days ago)
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 35.237.28.167 - - \[15/Sep/2026:17:18:52 +0200\] "GET /@fs/.env\?import\&\?raw\?\? HTTP/2.0" 301 402 "-" "Mozilla/5.0 \(compatible\; KimiBot/1.0\; +https://kimi.ai/\)"
35.237.28.167 - - \[15/Sep/2026:17:18:52 +0200\] "GET /@fs/.env\?url\&raw\?\? HTTP/2.0" 301 395 "-" "Mozilla/5.0 \(compatible\; cohere-ai\; +https://cohere.com/crawler\)"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-15 15:16:45
(5 days ago)
Try to access /.env?raw
Web App Attack
🇫🇮
as211431.net
2026-09-15 15:11:50
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /uploads../.env
UA: CCBot/2.0 (https://commoncrawl.org/faq/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
mnsf
2026-09-15 15:06:02
(5 days ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
Anonymous
2026-09-15 15:01:00
(5 days ago)
[ns65.kdns.gr] httpd-config-scan: sites=www.dcons.gr; logs=/var/log/httpd/domains/dcons.gr.log; samp ...
show more
[ns65.kdns.gr] httpd-config-scan: sites=www.dcons.gr; logs=/var/log/httpd/domains/dcons.gr.log; samples=/settings%2F.env | /@fs/.env?url&raw?? | /@fs/.env?import&?raw??
show less
Hacking
Web App Attack
🇺🇸
dot.mg
2026-09-15 15:00:30
(5 days ago)
Scan of vulnerable files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 14:53:35
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 35.237.28.167 (167.28.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.237.28.167 (167.28.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:53:27.990329 2026] [security2:error] [pid 26122:tid 26122] [client 35.237.28.167:33654] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dcagroupusa.com"] [uri "/z9x8c7v6b5-debug-trigger-dcagroupusa.com"] [unique_id "aqlb5_eSzNal_6FsbwZcEwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-15 14:53:32
(5 days ago)
35.237.28.167 - - [15/Sep/2026:22:53:31 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../pr ...
show more
35.237.28.167 - - [15/Sep/2026:22:53:31 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.237.28.167 - - [15/Sep/2026:22:53:32 +0800] "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
35.237.28.167 - - [15/Sep/2026:22:53:32 +0800] "GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 7813 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.237.28.167 - - [15/Sep/2026:22:53:32 +0800] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 7820 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.237.28.167 - - [15/Sep/2026:22:53:32 +0800] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/env
...
show less
Brute-Force
Anonymous
2026-09-15 14:52:51
(5 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇩🇪
Skyrider
2026-09-15 14:48:44
(5 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-15 14:48:43
(5 days ago)
(modsecurity) srv104 ModSecurity 35.237.28.167 (US/United States/167.28.237.35.bc.googleusercontent. ...
show more
(modsecurity) srv104 ModSecurity 35.237.28.167 (US/United States/167.28.237.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-15 14:20:58
(5 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-15 14:19:21
(5 days ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-15 13:59:37
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.28.167 (167.28.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:59:30.896702 2026] [security2:error] [pid 15732:tid 15732] [client 35.237.28.167:48434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidjschultz.com"] [uri "/%2e%2e/.env"] [unique_id "aqlPQhYBmjscTVcZPyZOxQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 13:51:31
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking