🇩🇪
LRob
2026-09-06 21:06:10
(2 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /rclone.conf (+2 more) | 2026-09-06 21:06 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-06 20:27:02
(41 minutes ago)
Portscan: TCP/8443 (6x), TCP/8080 (4x), TCP/80, TCP/443
Port Scan
🇺🇸
mnsf
2026-09-06 20:05:12
(1 hour ago)
Abuse Detected (10)
Brute-Force
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 19:15:20
(1 hour ago)
Try to access /.aws/credentials
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:03:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.6.188 (188.6.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.6.188 (188.6.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:03:39.876311 2026] [security2:error] [pid 32722:tid 32722] [client 35.238.6.188:54514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juliagouge.benshermanguitar.com"] [uri "/@fs/var/task/.env"] [unique_id "ap25CwbjYI_PJohKxP9IXgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TAY
2026-09-06 18:17:36
(2 hours ago)
35.238.6.188 - - [07/Sep/2026:02:17:34 +0800] "GET /public/plugins/grafana-clock-panel/../../../../. ...
show more
35.238.6.188 - - [07/Sep/2026:02:17:34 +0800] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.238.6.188 - - [07/Sep/2026:02:17:34 +0800] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
35.238.6.188 - - [07/Sep/2026:02:17:34 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 301 398 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
35.238.6.188 - - [07/Sep/2026:02:17:34 +0800] "GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 301 399 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.238.6.188 - - [07/Sep/2026:02:17:34 +0800] "GET /api/w/default/jobs
...
show less
Brute-Force
🇨🇭
zynex
2026-09-06 18:02:02
(3 hours ago)
URL Probing: /.env
Web App Attack
🇳🇱
Savvii
2026-09-06 17:07:36
(4 hours ago)
20 attempts against mh-misbehave-ban on grape
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:37:53
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.238.6.188 (188.6.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.6.188 (188.6.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:37:47.632857 2026] [security2:error] [pid 1298:tid 1298] [client 35.238.6.188:32884] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kirbysheetmetalworks.kirbysmw.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kirbysheetmetalworks.kirbysmw.com"] [uri "/rclone.conf"] [unique_id "ap2W29g3knNbKP7jq0642wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-06 16:22:57
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /images../.env
UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇫🇷
dynamix
2026-09-06 16:16:33
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇧🇬
HighWay
2026-09-06 15:25:39
(5 hours ago)
35.238.6.188 - - [06/Sep/2026:15:25:32 +0000] "GET /img../.env HTTP/1.1" 403 4346 "-" "Mozilla/5.0 ( ...
show more
35.238.6.188 - - [06/Sep/2026:15:25:32 +0000] "GET /img../.env HTTP/1.1" 403 4346 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
35.238.6.188 - - [06/Sep/2026:15:25:32 +0000] "GET /@fs/var/task/.env?raw?? HTTP/1.1" 403 421 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.238.6.188 - - [06/Sep/2026:15:25:32 +0000] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1" 403 421 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
...
show less
Port Scan
Bad Web Bot
Web App Attack
🇩🇪
abuse-detection
2026-09-06 15:09:13
(5 hours ago)
Web security detection (http-sensitive-probe); path=/__vite_rsc_findSourceMapURL; status=301
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-06 14:15:04
(6 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 14:12:44
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.6.188 (188.6.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.6.188 (188.6.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:12:37.207902 2026] [security2:error] [pid 497:tid 497] [client 35.238.6.188:51130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kingdomofgodbooks.org.halotoys.com"] [uri "/.env.old"] [unique_id "ap101enQ-EQLv6BMasNMLwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack