๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-31 04:16:31
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-open-proxy
Web App Attack
๐ต๐ฑ
sefinek.net
2026-04-08 19:44:25
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 12:34:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 07:34:05.112599 2026] [security2:error] [pid 14460:tid 14460] [client 65.111.9.127:29587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "questiondezyn.com"] [uri "/v2/.git/config"] [unique_id "aZG9PaWHAt4EibggY-O0MwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 11:19:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:19:46.049766 2026] [security2:error] [pid 699699:tid 699707] [client 65.111.9.127:29261] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ouye.org"] [uri "/app/.git/config"] [unique_id "aZGr0j6RhBWn5rx309keOQAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-15 07:05:48
(6 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
myagent.site
2026-02-15 06:29:00
(6 months ago)
Blocking for trying to access an exploit file: /dev/.git/config
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-15 06:20:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:20:05.518025 2026] [security2:error] [pid 11303:tid 11303] [client 65.111.9.127:53735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scifitimeline.com"] [uri "/backend/.env"] [unique_id "aZFllVxGpEhs_tzpxciOEQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2026-02-15 06:10:26
(6 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 05:54:25
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:54:20.168169 2026] [security2:error] [pid 11441:tid 11441] [client 65.111.9.127:14263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "professionalpartyplanner.org"] [uri "/app/.env"] [unique_id "aZFfjGpLwr1tUQZdWU2czgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 05:24:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:24:33.724924 2026] [security2:error] [pid 18185:tid 18204] [client 65.111.9.127:48729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oftv.xyz"] [uri "/frontend/.env"] [unique_id "aZFYkf5BqIWf3sZml9F6ggAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 05:17:56
(6 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:58:33
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:58:28.030843 2026] [security2:error] [pid 18955:tid 18955] [client 65.111.9.127:37317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahpeebles.net"] [uri "/site/.git/config"] [unique_id "aZFSdGw3B3JIuOBzZCl1-wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-02-15 04:34:32
(6 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:10:37
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.9.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:10:32.029891 2026] [security2:error] [pid 3071:tid 3071] [client 65.111.9.127:58001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samanthasomers.com"] [uri "/config/.env"] [unique_id "aZFHOGqRIEtIVEQbrbFBTgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack