🇺🇸
TPI-Abuse
2026-09-09 01:59:56
(26 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:59:51.072072 2026] [security2:error] [pid 14388:tid 14388] [client 8.135.32.208:61110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scriptediting.uk"] [uri "/.env"] [unique_id "aqC9l2C9VvLkIpz2vvUTdgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
pinguin
2026-09-09 01:41:17
(45 minutes ago)
Triggered Cloudflare WAF (firewallManaged) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇮🇹
CoreTech srl
2026-09-09 01:18:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-09 03:13:55,572 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-09 03:13:55,572 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.132.227.123 - 2026-09-09 03:13:55cloudlinux2 fail2ban: 2026-09-09 03:13:55,994 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 172.98.32.204 - 2026-09-09 03:13:55cloudlinux2 fail2ban: 2026-09-09 03:14:29,218 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 92.119.36.87 - 2026-09-09 03:14:28cloudlinux2 fail2ban: 2026-09-09 03:14:29,415 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 92.119.36.72 - 2026-09-09 03:14:28cloudlinux2 fail2ban: 2026-09-09 03:15:13,052 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.73.161.224 - 2026-09-09 03:15:12cloudlinux2 fail2ban: 2026-09-09 03:16:05,425 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 8.135.32.208 - 2026-09-09 03:16:04cloudlinux2 fail2ban: 2026-09-09 03:16:49,788 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 170.101.96.37 - 2026-09-09 03:16:49cloudl
show less
Web App Attack
🇹🇷
oalver
2026-09-09 00:56:57
(1 hour ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.env (HTTP 301). First seen: 2026-09-08. Risk score: 30/100.
show less
Web App Attack
🇬🇧
gurnip
2026-09-08 22:21:57
(4 hours ago)
Vulnerability probe of page /.env, not found on server.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:55:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:55:22.694595 2026] [security2:error] [pid 10668:tid 10668] [client 8.135.32.208:62559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yourmac.co.uk"] [uri "/.env"] [unique_id "aqCESg4U_MP3AHIN2cMavAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
spot
2026-09-08 21:15:32
(5 hours ago)
8.135.32.208 - - [08/Sep/2026:22:15:31 +0100] "GET /.env HTTP/1.1" 301 636 "-" "Mozilla/5.0 (X11; Li ...
show more
8.135.32.208 - - [08/Sep/2026:22:15:31 +0100] "GET /.env HTTP/1.1" 301 636 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
VPN IP
🇮🇪
Jim Keir
2026-09-08 20:39:47
(5 hours ago)
2026-09-08 20:39:47 8.135.32.208 File scanning, blocking 8.135.32.208 for 5 minutes
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:12:48
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:12:42.170122 2026] [security2:error] [pid 1439:tid 1439] [client 8.135.32.208:63659] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipport.co.uk"] [uri "/.env"] [unique_id "aqBCCmmu6ZzlBHoqV3pGywAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:23:02
(10 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, POST / HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:27:36
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:27:30.683383 2026] [security2:error] [pid 17141:tid 17141] [client 8.135.32.208:61081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powersystemprotection.co.uk"] [uri "/.env"] [unique_id "aqAbUoTbvS7uFv5m20K6PgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:25:25
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:25:21.764843 2026] [security2:error] [pid 27428:tid 27428] [client 8.135.32.208:51421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oxford-gliding-club.co.uk"] [uri "/.env"] [unique_id "aqAMwV4Zcvce9CGywJDdMAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:18:10
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 8.135.32.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:18:01.641703 2026] [security2:error] [pid 14194:tid 14194] [client 8.135.32.208:56023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natashahenry.co.uk"] [uri "/.env"] [unique_id "ap_8-VWjCqHxbvbhlZmp_QAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
myintarweb
2026-09-08 10:47:30
(15 hours ago)
8.135.32.208 - - [08/Sep/2026:11:47:29 +0100] 80 "GET /.env HTTP/1.1" 301 1633 "-" "Mozilla/5.0 (X11 ...
show more
8.135.32.208 - - [08/Sep/2026:11:47:29 +0100] 80 "GET /.env HTTP/1.1" 301 1633 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇬🇧
Yosi
2026-09-08 09:09:58
(17 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force