Anonymous
2025-04-20 19:48:29
(1 year ago)
$f2bV_matches
Brute-Force
πΊπΈ
CollinsCorner
2025-04-14 20:11:00
(1 year ago)
Caught scraping for vulnerable files and/or endpoints - =3
Bad Web Bot
Web App Attack
πΊπΈ
Mehmet_The_Script_Kiddie
2025-04-14 18:18:03
(1 year ago)
CloudFlare WAF REPORT: /.env
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-04-14 15:03:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 11:03:48.262114 2025] [security2:error] [pid 26249:tid 26249] [client 54.37.237.174:57497] [client 54.37.237.174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.23"] [uri "/.env"] [unique_id "Z_0j1Alry-BJEZ_cV_9pDwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Syxpi_Lumi
2025-04-14 12:00:06
(1 year ago)
Triggered Cloudflare WAF (botFight) from FR.
Action taken: MANAGED_CHALLENGE
ASN: 16276 (OVH)
Protoc ...
show more
Triggered Cloudflare WAF (botFight) from FR.
Action taken: MANAGED_CHALLENGE
ASN: 16276 (OVH)
Protocol: HTTP/1.1 (GET method)
Timestamp: 2025-04-14T09:21:07Z
UA: python-requests/2.26.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πͺπΈ
masterguru
2025-04-14 11:50:44
(1 year ago)
BAD BOT - Detected and Blocked.. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. (11 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "python-requests" at REQUEST_HEADERS:User-Agent. (1100000-123)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-04-14 10:53:05
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 06:53:00.597416 2025] [security2:error] [pid 30016:tid 30016] [client 54.37.237.174:57625] [client 54.37.237.174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lovetank.net"] [uri "/.env"] [unique_id "Z_zpDNGMhYFniDIWTyuvdgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
el-brujo
2025-04-14 09:55:21
(1 year ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: foro.elhacker.net userAgent: python-reques ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: foro.elhacker.net userAgent: python-requests/2.26.0 Action: block Source: firewallManaged ASN Description: OVH Country: FR Method: GET Timestamp: 2025-04-14T09:55:21Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
πΊπΈ
TPI-Abuse
2025-04-14 09:20:42
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 05:20:39.062525 2025] [security2:error] [pid 3921219:tid 3921219] [client 54.37.237.174:61549] [client 54.37.237.174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.massivepro.com"] [uri "/.env"] [unique_id "Z_zTZzBoOJcTf3qA71V_TQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-04-14 08:27:10
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 04:27:03.859843 2025] [security2:error] [pid 26612:tid 26612] [client 54.37.237.174:54277] [client 54.37.237.174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tracytappan.net"] [uri "/.env"] [unique_id "Z_zG1-Hq_cWz7D1KGKyrJgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2025-04-14 08:15:14
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-04-14 08:04:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 04:04:49.909760 2025] [security2:error] [pid 3286160:tid 3286160] [client 54.37.237.174:59816] [client 54.37.237.174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.7"] [uri "/.env"] [unique_id "Z_zBofedcR4ait7BIR6COwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
lindi
2025-04-14 08:00:49
(1 year ago)
trying to access .env file
...
Hacking
Web App Attack
π¨π
teamsecure
2025-04-14 07:52:40
(1 year ago)
Banned for trying to access env
Web App Attack
πΊπΈ
TPI-Abuse
2025-04-14 07:43:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 54.37.237.174 (ip174.ip-54-37-237.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 03:43:18.864933 2025] [security2:error] [pid 21242:tid 21242] [client 54.37.237.174:51701] [client 54.37.237.174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.5"] [uri "/.env"] [unique_id "Z_y8lkSNSDYvPygJwnvZLgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack