๐บ๐ธ
TPI-Abuse
2026-06-14 10:56:45
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:56:38.000163 2026] [security2:error] [pid 31112:tid 31211] [client 85.121.120.115:39264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rcorbet.net"] [uri "/.env.example"] [unique_id "ai6I5YWJIASSC6w0RvYrvAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-06-14 07:56:44
(6 hours ago)
85.121.120.115 - - [14/Jun/2026:08:56:44 +0100] "GET /application.yml HTTP/2.0" 401 410 "-" "Mozilla ...
show more
85.121.120.115 - - [14/Jun/2026:08:56:44 +0100] "GET /application.yml HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
2026-06-14 07:39:03
(6 hours ago)
Unauthorized SSH login attempts
Brute-Force
SSH
๐ฉ๐ช
Bedios GmbH
2026-06-14 07:01:09
(7 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-14 04:25:08
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 00:25:02.122882 2026] [security2:error] [pid 8262:tid 8262] [client 85.121.120.115:40484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raymondtbrown.com"] [uri "/.env.example"] [unique_id "ai4tHjj5GVVPoiZrILuoBgAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 03:43:41
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 23:43:37.687831 2026] [security2:error] [pid 13948:tid 13948] [client 85.121.120.115:46236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zenmonkeyproject.com"] [uri "/backend/.env"] [unique_id "ai4jaYwaWxOEJy7QQFm9nwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Moby
2026-06-14 03:19:50
(11 hours ago)
85.121.120.115 - - [13/Jun/2026:22:19:43 -0500] "GET /api/.env HTTP/1.1" 404 984 "-" "Mozilla/5.0 (c ...
show more
85.121.120.115 - - [13/Jun/2026:22:19:43 -0500] "GET /api/.env HTTP/1.1" 404 984 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" "75.88.18.218" "techspace.cc"
85.121.120.115 - - [13/Jun/2026:22:19:46 -0500] "GET /.env.example HTTP/1.1" 404 984 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "75.88.18.218" "techspace.cc"
85.121.120.115 - - [13/Jun/2026:22:19:46 -0500] "GET /secrets.yml HTTP/1.1" 404 984 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot" "75.88.18.218" "techspace.cc"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 03:18:22
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 23:18:18.502121 2026] [security2:error] [pid 20216:tid 20219] [client 85.121.120.115:51446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rawsynergy.com"] [uri "/.env"] [unique_id "ai4denFYHTlLDE1PmXFDzgAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-06-14 01:36:00
(12 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ซ๐ท
mrcrassi
2026-06-13 22:23:24
(16 hours ago)
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /env.json
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-06-13 19:57:55
(18 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 15:44:03
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 11:43:55.221407 2026] [security2:error] [pid 7257:tid 7257] [client 85.121.120.115:58390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rapidheatprocesses.com"] [uri "/.env"] [unique_id "ai16u-1Q01U3k90Zhr3FawAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 04:45:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 00:45:09.593391 2026] [security2:error] [pid 3802:tid 3802] [client 85.121.120.115:54128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "randeen.com"] [uri "/.env"] [unique_id "aizgVbbUDedObpp8vrnCegAAADw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 04:28:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 85.121.120.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 00:28:45.512732 2026] [security2:error] [pid 25758:tid 25758] [client 85.121.120.115:57484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gregorii.com"] [uri "/.env"] [unique_id "aizcfQ7AHoh_u0gDG23KqwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-13 02:33:07
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot