π©πͺ
febrian.de
2026-06-23 06:45:22
(20 hours ago)
Excessive HTTP(S) probing or bad web bot detected by Fail2Ban
Bad Web Bot
Web App Attack
Anonymous
2026-05-22 17:33:48
(1 month ago)
[Fri May 22 19:33:46.868303 2026] [authz_core:error] [pid 19409] [client 104.23.217.126:10930] AH016 ...
show more
[Fri May 22 19:33:46.868303 2026] [authz_core:error] [pid 19409] [client 104.23.217.126:10930] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 22 19:33:47.024749 2026] [authz_core:error] [pid 19409] [client 104.23.217.126:10930] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 22 19:33:47.228460 2026] [authz_core:error] [pid 19409] [client 104.23.217.126:10930] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π·πΊ
DZBOT
2026-05-22 14:07:39
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π©πͺ
big-cloud.nl
2026-05-17 18:20:45
(1 month ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 16:52:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.126 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 12:52:41.074664 2026] [security2:error] [pid 17695:tid 17695] [client 104.23.217.126:12960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "purlandpurr.com"] [uri "/.git/config"] [unique_id "agnyWWhIdnx2wigHY8coWAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 14:25:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.126 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 10:25:45.168731 2026] [security2:error] [pid 9108:tid 9108] [client 104.23.217.126:9880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaleidoscope-glass.com"] [uri "/.git/config"] [unique_id "agnP6fbH4YkWAMkCQI3S7QAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-05-16 21:59:04
(1 month ago)
Auto-ban: >3000 req/min op 2026-05-16
Web App Attack
SSH
Hacking
π©πͺ
bescared
2026-05-13 07:06:05
(1 month ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 11:56:57
(1 month ago)
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy ...
show more
Probing for known exploit paths (.env, .git, wp-admin, shell files, etc.). Single-strike ban policy β zero tolerance for exploit scanning. Banned May 12, 11:56 UTC. Origin: Sweden, Stockholm.
show less
Hacking
Bad Web Bot
Web App Attack
π¬π§
pinguin
2026-05-08 01:09:14
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from SE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from SE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /config.js
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π«π·
vtchost.com
2026-05-04 03:54:14
(1 month ago)
formandserif.com:80 104.23.217.126 - - [04/May/2026:05:54:14 +0200] "GET /wp-admin/install.php?step= ...
show more
formandserif.com:80 104.23.217.126 - - [04/May/2026:05:54:14 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 403 429 "-" "http://formandserif.com/wp-admin/install.php?step=1"
...
show less
Web App Attack
Anonymous
2026-04-22 13:15:45
(2 months ago)
[Wed Apr 22 15:15:44.803105 2026] [authz_core:error] [pid 28562] [client 104.23.217.126:14234] AH016 ...
show more
[Wed Apr 22 15:15:44.803105 2026] [authz_core:error] [pid 28562] [client 104.23.217.126:14234] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Apr 22 15:15:44.843283 2026] [authz_core:error] [pid 28562] [client 104.23.217.126:14234] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Apr 22 15:15:44.967668 2026] [authz_core:error] [pid 28562] [client 104.23.217.126:14234] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-21 07:18:51
(2 months ago)
[Tue Apr 21 09:18:50.308388 2026] [authz_core:error] [pid 3343] [client 104.23.217.126:11226] AH0163 ...
show more
[Tue Apr 21 09:18:50.308388 2026] [authz_core:error] [pid 3343] [client 104.23.217.126:11226] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Apr 21 09:18:50.347489 2026] [authz_core:error] [pid 3343] [client 104.23.217.126:11226] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Apr 21 09:18:50.379765 2026] [authz_core:error] [pid 3343] [client 104.23.217.126:11226] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π«π·
security.yc3a.com
2026-04-18 02:52:50
(2 months ago)
104.23.217.126 - - [18/Apr/2026:02:52:49 +0000] "GET /wp-login.php HTTP/2.0" 301 162 "https://www.go ...
show more
104.23.217.126 - - [18/Apr/2026:02:52:49 +0000] "GET /wp-login.php HTTP/2.0" 301 162 "https://www.google.com" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
Anonymous
2026-04-16 13:03:24
(2 months ago)
[Thu Apr 16 15:03:23.939112 2026] [authz_core:error] [pid 9549] [client 104.23.217.126:12855] AH0163 ...
show more
[Thu Apr 16 15:03:23.939112 2026] [authz_core:error] [pid 9549] [client 104.23.217.126:12855] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Apr 16 15:03:23.982867 2026] [authz_core:error] [pid 9549] [client 104.23.217.126:12855] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Apr 16 15:03:24.030949 2026] [authz_core:error] [pid 9549] [client 104.23.217.126:12855] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack