๐บ๐ธ
TPI-Abuse
2026-07-31 08:40:21
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 46.232.235.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 46.232.235.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 04:40:06.567636 2026] [security2:error] [pid 3053832:tid 3053832] [client 46.232.235.4:60228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weedifyit.pswebsite.com"] [uri "/.git/config"] [unique_id "amxfZpuxs7F2k-GQxcQOXwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
bokumin.org
2026-07-31 06:13:46
(3 hours ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.env"] [id "949110"] [m ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.env"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
๐ซ๐ท
Baking333
2026-07-31 06:10:07
(3 hours ago)
[redacted] 46.232.235.4 - - [31/Jul/2026:07:10:03 +0100] "GET /.env HTTP/1.1" 302 1528 0/250169 "-" ...
show more
[redacted] 46.232.235.4 - - [31/Jul/2026:07:10:03 +0100] "GET /.env HTTP/1.1" 302 1528 0/250169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:108.0) Gecko/20100101 Firefox/108.0" [redacted] 46.232.235.4 - - [31/Jul/2026:07:10:04 +0100] "GET /.git/config HTTP/1.1" 302 1528 0/84384 "-" "Mozilla/5.0 (Kubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-31 06:00:03
(3 hours ago)
suspicious request in access.log
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-31 06:00:00
(3 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-07-31 05:21:19
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 04:24:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 46.232.235.4 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 46.232.235.4 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 00:24:35.657703 2026] [security2:error] [pid 230886:tid 230886] [client 46.232.235.4:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "journal.luisguacache.com"] [uri "/.git/config"] [unique_id "amwjg38KuSlr7yHNoSzrDQAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-31 03:50:59
(5 hours ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ต๐ซ
www.gregorymariani.com
2026-07-31 03:43:39
(5 hours ago)
46.232.235.4 - - [31/Jul/2026:02:37:21 +0000] "GET /.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Windows ...
show more
46.232.235.4 - - [31/Jul/2026:02:37:21 +0000] "GET /.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.18363" 525 0.003 [default-fenua-web-svc-80] [] 10.244.8.151:8000 179 0.003 404 9a3b637fb88be056d26eb1f09e9c1905
46.232.235.4 - - [31/Jul/2026:02:37:21 +0000] "GET /.git/config HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36" 520 0.001 [default-fenua-web-svc-80] [] 10.244.8.151:8000 179 0.002 404 a10fd580f6e1c886eb996159c17dbffd
46.232.235.4 - - [31/Jul/2026:03:13:21 +0000] "GET /.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Windows NT 10.0; rv:68.0) Gecko/20100101 Firefox/68.0" 462 0.004 [default-fenua-web-svc-80] [] 10.244.8.151:8000 179 0.005 404 9cf6df910e541f4d0cd42d818b886df2
46.232.235.4 - - [31/Jul/2026:03:13:23 +0000] "GET /.git/config HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Macintosh; Intel Mac
...
show less
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-07-31 03:27:37
(5 hours ago)
dot file probe
Web App Attack
๐ท๐บ
DZBOT
2026-07-31 03:04:01
(6 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-07-31 02:08:41
(7 hours ago)
Probing for non-installed web apps or current vulnerabilities.
Hacking
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-31 00:54:53
(8 hours ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
NerdyMcNerderson
2026-07-31 00:53:38
(8 hours ago)
MarekCloud auto-ban: ENV leak probe: GET /.env
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-30 23:59:12
(9 hours ago)
(y3) Failed access -byebye- from 46.232.235.4 (DE/Germany/-): (CF_ENABLE)
Hacking