๐บ๐ธ
SketchyDude
2026-08-27 22:14:40
(44 minutes ago)
Banned by Fail2Ban jail: apache-auth
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:00:58
(57 minutes ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฐ๐ท
HexByte
2026-08-27 21:25:04
(1 hour ago)
[daon] Web scan/abuse: 1 events (web_probe). paths: GET /.env.local -> 404. sample: 35.254.128.112 - ...
show more
[daon] Web scan/abuse: 1 events (web_probe). paths: GET /.env.local -> 404. sample: 35.254.128.112 - - [28/Aug/2026:06:25:04 +0900] "GET /.env.local HTTP/1.1" 404 207 "-" "crusader-worker/1.0"
show less
Web App Attack
Hacking
๐บ๐ธ
jkhorvath.com
2026-08-27 21:05:55
(1 hour ago)
Request for URL /.env.bak
Phishing
Brute-Force
Web App Attack
๐ง๐พ
lns.bz
2026-08-27 19:39:37
(3 hours ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 19:32:13
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ซ๐ฎ
as211431.net
2026-08-27 19:08:58
(3 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //.env
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฆ
polycoda
2026-08-27 18:05:13
(4 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:57:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.128.112 (112.128.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.128.112 (112.128.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:57:29.729483 2026] [security2:error] [pid 8008:tid 8008] [client 35.254.128.112:40174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "femalestripperslaquinta.com"] [uri "/.env.production"] [unique_id "apB6ic84EM2n5XKeehoj4AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
relianoid.com
2026-08-27 17:54:50
(5 hours ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-27 17:48:54
(5 hours ago)
Banned by Fail2Ban
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-27 17:20:12
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 17:05:17
(5 hours ago)
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /wp-config.php~ HTTP/1.1" 307 4567 "-" "crusade ...
show more
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /wp-config.php~ HTTP/1.1" 307 4567 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /wp-config.php.bak HTTP/1.1" 307 4573 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /.env.old HTTP/1.1" 307 4555 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /crusader-404-probe HTTP/1.1" 307 4575 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /_ignition/health-check HTTP/1.1" 307 4583 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /actuator/env HTTP/1.1" 307 4563 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /.env.example HTTP/1.1" 307 4563 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 307 4586 "-" "crusader-worker/1.0"
35.254.128.112 - - [27/Aug/2026:19:05:15 +0200] "GET /.env.production HTT
show less
Web App Attack
Brute-Force
Anonymous
2026-08-27 17:01:02
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /.env.old HTTP/1.1 ...
show more
Bot / scanning and/or hacking attempts: GET /_ignition/health-check HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.bak HTTP/1.1, GET /wp-config.php.bak HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:31:45
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.128.112 (112.128.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.128.112 (112.128.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:31:38.118134 2026] [security2:error] [pid 14347:tid 14347] [client 35.254.128.112:53888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flinthillsveterans.org"] [uri "/.env.old"] [unique_id "apBmapUe04d8_8N4LXemzwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack