๐ณ๐ฑ
homeshowdomain.nl
2026-07-18 22:02:27
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-17.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 21:59:40
(2 days ago)
Auto-ban: >3000 req/min op 2026-07-17
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 06:00:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 02:00:22.222385 2026] [security2:error] [pid 505:tid 556] [client 52.8.219.129:31906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjstauffer.com"] [uri "/.env.prod"] [unique_id "alnE9rcXu39QGnMhrP36LwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-17 05:35:31
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 04:43:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 00:43:17.775546 2026] [security2:error] [pid 240384:tid 240384] [client 52.8.219.129:59998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coiledtubingdrilling.com.antech.net"] [uri "/.env.development"] [unique_id "almy5TdMdfjLVc5PZLgnjQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 04:17:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 00:17:03.737191 2026] [security2:error] [pid 14729:tid 14729] [client 52.8.219.129:38260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "go-901.com"] [uri "/.env.backup"] [unique_id "almsv2eWe9_fT7Ksk55NbgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 03:55:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 23:55:08.085640 2026] [security2:error] [pid 228586:tid 228586] [client 52.8.219.129:62070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.web.kentculotta.com"] [uri "/.env.swp"] [unique_id "almnnEaUgi3nWs4N21rM_wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-07-17 03:24:41
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /laravel/.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-07-17 03:08:16
(2 days ago)
{"reqId":"klDH3mLrOx4Og59J1W5w","level":1,"time":"2026-07-17T05:06:30+02:00","remoteAddr":"52.8.219. ...
show more
{"reqId":"klDH3mLrOx4Og59J1W5w","level":1,"time":"2026-07-17T05:06:30+02:00","remoteAddr":"52.8.219.129","user":"--","app":"core","method":"GET","url":"/settings.json","scriptName":"/index.php","message":"Trusted domain error. \"52.8.219.129\" tried to access using \"home.khomri.com\" as host.","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)","version":"34.0.1.2","data":{"app":"core"}}
{"reqId":"QWQgneAF2AMhzQpYYAEj","level":1,"time":"2026-07-17T05:06:34+02:00","remoteAddr":"52.8.219.129","user":"--","app":"core","method":"GET","url":"/secrets.json","scriptName":"/index.php","message":"Trusted domain error. \"52.8.219.129\" tried to access using \"home.khomri.com\" as host.","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 03:06:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 23:06:48.163784 2026] [security2:error] [pid 11706:tid 11706] [client 52.8.219.129:12086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mitchell238.macryder.com"] [uri "/.env.save"] [unique_id "almcSAFb5IkpK6O5MRfnowAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-17 02:53:03
(2 days ago)
csagent: score 19.6: secrets grab x2; 2 domain(s) in 7s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 01:24:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:24:42.482040 2026] [security2:error] [pid 10283:tid 10283] [client 52.8.219.129:23892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susansambou.org"] [uri "/.env.production"] [unique_id "almEWpKw9SRwc5wWXsk4EQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 00:57:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.8.219.129 (ec2-52-8-219-129.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 20:57:37.719794 2026] [security2:error] [pid 57020:tid 57020] [client 52.8.219.129:15658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "victorvictor.biz"] [uri "/wp-config.php~"] [unique_id "all-Aag1ruiC0cK8VbSCbAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-17 00:09:02
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
KiekerJan
2026-07-17 00:03:14
(3 days ago)
52.8.219.129 - - [17/Jul/2026:02:03:13 +0200] "GET /.env.production.local HTTP/1.1" 404 548 "-" "Moz ...
show more
52.8.219.129 - - [17/Jul/2026:02:03:13 +0200] "GET /.env.production.local HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
52.8.219.129 - - [17/Jul/2026:02:03:13 +0200] "GET /.env.development.local HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
...
show less
Web App Attack