๐ง๐ฌ
fennaronaldo
2026-07-21 14:13:31
(3 hours ago)
WAF block action triggered by rule set "Version Control - Information Disclosure" (1 occurrences obs ...
show more
WAF block action triggered by rule set "Version Control - Information Disclosure" (1 occurrences observed).
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-18 07:41:35
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐จ๐ญ
TheCoon
2026-07-18 07:00:02
(3 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฎ๐ณ
evicky2002
2026-07-18 06:00:00
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 22:03:51
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-16.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-07-17 18:02:02
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 54.241.47.158 (US/United States/ec2-54- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 54.241.47.158 (US/United States/ec2-54-241-47-158.us-west-1.compute.amazonaws.com)
show less
SQL Injection
๐ซ๐ฎ
as211431.net
2026-07-17 17:56:00
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env~
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-17 13:09:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 09:09:14.142318 2026] [security2:error] [pid 30325:tid 30325] [client 54.241.47.158:6724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "consorciolegal.com"] [uri "/.env"] [unique_id "alopeqOAasN0cc1Nc19xzQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 11:38:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:38:07.316534 2026] [security2:error] [pid 17579:tid 17579] [client 54.241.47.158:6852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lanegraves.com"] [uri "/.env"] [unique_id "aloUH-j2lUQBlWLFNOpMLAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 11:15:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:15:21.845782 2026] [security2:error] [pid 18181:tid 18216] [client 54.241.47.158:17470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thebiglies.com"] [uri "/.env"] [unique_id "aloOySF2bUEiMTRn3YNA7wAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:50:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:50:44.366375 2026] [security2:error] [pid 3901539:tid 3901539] [client 54.241.47.158:40510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "20dekopas.com"] [uri "/frontend/.env"] [unique_id "aloJBJnsZh7L_UNP-Fzv0gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski
2026-07-17 10:22:11
(4 days ago)
IVski WAF | Sensitive file probe detected - looking for .env
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:21:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.241.47.158 (ec2-54-241-47-158.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:21:17.159127 2026] [security2:error] [pid 18164:tid 18164] [client 54.241.47.158:53376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sandersgroundtest.ryanc.net"] [uri "/.env.development"] [unique_id "aloCHYa8Dz54rZ77mkBA1wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-17 09:55:53
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-17 09:44:00
(4 days ago)
(modsecurity) srv201 ModSecurity 54.241.47.158 (US/United States/ec2-54-241-47-158.us-west-1.compute ...
show more
(modsecurity) srv201 ModSecurity 54.241.47.158 (US/United States/ec2-54-241-47-158.us-west-1.compute.amazonaws.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack