๐ฉ๐ช
Dominik Lysiak
2026-06-20 09:35:52
(2 hours ago)
45.130.203.161 - - [20/Jun/2026:11:35:44 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Python-urllib/3.10 ...
show more
45.130.203.161 - - [20/Jun/2026:11:35:44 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Python-urllib/3.10"
45.130.203.161 - - [20/Jun/2026:11:35:50 +0200] "GET /.env HTTP/1.1" 444 0 "-" "Python-urllib/3.10"
45.130.203.161 - - [20/Jun/2026:11:35:52 +0200] "GET /.env.production HTTP/1.1" 401 172 "-" "Python-urllib/3.10"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 06:01:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 02:01:04.183323 2026] [security2:error] [pid 14490:tid 14490] [client 45.130.203.161:26195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "text.joebankx.com"] [uri "/.git/HEAD"] [unique_id "ajYsoORRqvdNuR-yqc-6NAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-06-20 05:57:00
(6 hours ago)
F2B - Malicious activity detected. URL Probing. -c0423ad6-
Hacking
Web App Attack
๐ฉ๐ช
strxmpp
2026-06-20 02:21:09
(10 hours ago)
45.130.203.161 - - [20/Jun/2026:04:21:08 +0200] "GET /.git/HEAD HTTP/1.1" 404 503 "-" "Python-urllib ...
show more
45.130.203.161 - - [20/Jun/2026:04:21:08 +0200] "GET /.git/HEAD HTTP/1.1" 404 503 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-20 01:20:40
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 21:20:35.581986 2026] [security2:error] [pid 8235:tid 8235] [client 45.130.203.161:49195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluesbluff.varnadorefamily.com"] [uri "/.git/HEAD"] [unique_id "ajXq4yXXf--_OKen5vovTgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-06-19 13:06:56
(23 hours ago)
Suricata: Alert - ET INFO Request to Hidden Environment File - Inbound
Web App Attack
๐ฌ๐ง
Axel
2026-06-19 10:29:51
(1 day ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env.product ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env.production Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-19 06:45:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.161 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 02:45:21.045812 2026] [security2:error] [pid 19077:tid 19077] [client 45.130.203.161:47445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.aticom.net"] [uri "/.env"] [unique_id "ajTlgb6yoF5d_MjA8VADTAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-06-19 00:09:03
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-06-18 22:27:50
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ณ๐ฑ
tmiland
2026-06-18 12:56:31
(1 day ago)
(nginx_404) Dot directory Honeypot Trap 45.130.203.161 (DZ/Algeria/-): 2 in the last 3600 secs; IP: ...
show more
(nginx_404) Dot directory Honeypot Trap 45.130.203.161 (DZ/Algeria/-): 2 in the last 3600 secs; IP: 45.130.203.161; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.130.203.161 - - [18/Jun/2026:14:55:49 +0200] "GET /.env HTTP/1.1" 404 2992 "-" "Python-urllib/3.10" 45.130.203.161 - - [18/Jun/2026:14:56:27 +0200] "GET /.env HTTP/1.1" 404 146 "-" "Python-urllib/3.10"
show less
Brute-Force
Anonymous
2026-06-17 17:41:02
(2 days ago)
Malicious activity detected
Hacking
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-17 07:15:31
(3 days ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-17 08:15:31 UTC
Log evidence:
45.130.203.161 - - [17/Jun/2026:08:15:29 +0100] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Python-urllib/3.10"
06/17/2026-08:15:29.950866 [wDrop] [**] [1:7000910:1] FINSERV CRITICAL: Git Repository Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 45.130.203.161:35993 -> 185.127.18.66:80
06/17/2026-08:15:29.950866 [**] [1:1000112:1] SECURITY CRITICAL: Git Config File Access Attempt [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 45.130.203.161:35993 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
Anonymous
2026-06-10 19:56:31
(1 week ago)
45.130.203.161 - - [10/Jun/2026:21:56:22 +0200] "GET /retu11.PhP7 HTTP/1.1" 404 482 "-" "Mozilla/5.0 ...
show more
45.130.203.161 - - [10/Jun/2026:21:56:22 +0200] "GET /retu11.PhP7 HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
45.130.203.161 - - [10/Jun/2026:21:56:22 +0200] "GET /wp-content/themes/twentytwentytwo/bypass.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
45.130.203.161 - - [10/Jun/2026:21:56:22 +0200] "GET /wp-admin/css/elementskit.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
45.130.203.161 - - [10/Jun/2026:21:56:22 +0200] "GET /js/1.php7 HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0"
45.130.203.161 - - [10/Jun/2026:21:56:22 +0200] "GET /wp-content/themes/twentytwentyfour/install.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
DDoS Attack
๐ท๐บ
sms.ru
2026-06-10 17:53:21
(1 week ago)
/wp-admin/js/admin.php
Web App Attack