๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:01:49
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
gadix
2026-08-28 11:29:54
(5 days ago)
[28/Aug/2026:13:29:53.693698 +0200] apFxMRGF5MoCHC-iyTJBrQAAAEM 104.197.168.247 45652 127.0.0.1 7081 ...
show more
[28/Aug/2026:13:29:53.693698 +0200] apFxMRGF5MoCHC-iyTJBrQAAAEM 104.197.168.247 45652 127.0.0.1 7081
[28/Aug/2026:13:29:53.697364 +0200] apFxMRGF5MoCHC-iyTJBrgAAAFU 104.197.168.247 45674 127.0.0.1 7081
[28/Aug/2026:13:29:53.700260 +0200] apFxMRGF5MoCHC-iyTJBrwAAAEQ 104.197.168.247 45666 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:19:48
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.197.168.247 (247.168.197.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.168.247 (247.168.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:19:41.893627 2026] [security2:error] [pid 26755:tid 26755] [client 104.197.168.247:47430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cursos.logosformacion.net"] [uri "/.env.example"] [unique_id "apFuzU5YB2C3fGhIeTyWHgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 10:59:50
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
noise.agency
2026-08-28 05:40:57
(5 days ago)
(CT) IP 104.197.168.247 (US/United States/247.168.197.104.bc.googleusercontent.com) found to have 52 ...
show more
(CT) IP 104.197.168.247 (US/United States/247.168.197.104.bc.googleusercontent.com) found to have 527 connections
show less
DDoS Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:03:39
(6 days ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐น๐ท
muratkaya665
2026-08-27 21:51:03
(6 days ago)
IPS Attack Blocked by server.mura******.com.tr Fortigate-80E. Attack Name: Spring.Boot.Actuator.Unau ...
show more
IPS Attack Blocked by server.mura******.com.tr Fortigate-80E. Attack Name: Spring.Boot.Actuator.Unauthorized.Access. Dest Port: 80. Service: HTTP. Message: applications3: Spring.Boot.Actuator.Unauthorized.Access.
show less
Hacking
Anonymous
2026-08-27 21:44:08
(6 days ago)
Brute-Force reported by Fail2Ban
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-08-27 20:50:13
(6 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/web-asn-lockdown-high.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nevermind
2026-08-27 20:35:25
(6 days ago)
104.197.168.247 - - [27/Aug/2026:22:35:24 +0200] "GET /.env HTTP/1.1" 403 6273 "-" "crusader-worker/ ...
show more
104.197.168.247 - - [27/Aug/2026:22:35:24 +0200] "GET /.env HTTP/1.1" 403 6273 "-" "crusader-worker/1.0"
104.197.168.247 - - [27/Aug/2026:22:35:24 +0200] "GET /.env.backup HTTP/1.1" 403 6273 "-" "crusader-worker/1.0"
104.197.168.247 - - [27/Aug/2026:22:35:24 +0200] "GET /.env.example HTTP/1.1" 403 6273 "-" "crusader-worker/1.0"
104.197.168.247 - - [27/Aug/2026:22:35:24 +0200] "GET /.env.save HTTP/1.1" 403 6273 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
valornode
2026-08-27 19:35:09
(6 days ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-sensitive-files | ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-sensitive-files | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: US | Range: 104.196.0.0/14
show less
Brute-Force
SSH
๐ซ๐ท
ecode hosting
2026-08-27 19:25:04
(6 days ago)
Domain : alphasurveying.com.tr
Rule : hack
2026-08-27 19:23:00 10.100.1.20 GET /wp-config.php.bak - ...
show more
Domain : alphasurveying.com.tr
Rule : hack
2026-08-27 19:23:00 10.100.1.20 GET /wp-config.php.bak - 80 - 104.197.168.247 HTTP/1.1 crusader-worker/1.0 - alphasurveying.com.tr 301 0 0 361 110 180 - -
show less
Hacking
SQL Injection
Brute-Force
Anonymous
2026-08-27 19:24:42
(6 days ago)
Web application attack detected.
Web App Attack
๐ฌ๐ง
pinguin
2026-08-27 19:14:15
(6 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 19:03:29
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 104.197.168.247 (247.168.197.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.197.168.247 (247.168.197.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:03:21.108767 2026] [security2:error] [pid 19315:tid 19315] [client 104.197.168.247:36572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.anatolyaleksin.com"] [uri "/.env.production"] [unique_id "apCJ-WLU6JytbqjEi6H3iQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack