🇺🇸
TPI-Abuse
2026-08-28 01:29:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 13.213.68.167 (ec2-13-213-68-167.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.213.68.167 (ec2-13-213-68-167.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:29:02.852749 2026] [security2:error] [pid 8488:tid 8488] [client 13.213.68.167:45836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marxistphilosophy.org"] [uri "/.htpasswd"] [unique_id "apDkXjeElMefmPJsL15ScgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Lunix
2026-08-28 00:27:21
(2 weeks ago)
Brute-Force
Web App Attack
🇩🇪
Inamin
2026-08-27 23:43:08
(2 weeks ago)
13.213.68.167 - - [28/Aug/2026:07:43:06 +0800] "GET /login HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windo ...
show more
13.213.68.167 - - [28/Aug/2026:07:43:06 +0800] "GET /login HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
13.213.68.167 - - [28/Aug/2026:07:43:07 +0800] "GET /admin HTTP/2.0" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇬🇧
blik2108
2026-08-27 23:07:48
(2 weeks ago)
13.213.68.167 - - [27/Aug/2026:23:07:43 +0000] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 ...
show more
13.213.68.167 - - [27/Aug/2026:23:07:43 +0000] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "172.16.25.201"
13.213.68.167 - - [27/Aug/2026:23:07:43 +0000] "GET /.git/HEAD HTTP/1.1" 301 169 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "172.30.203.157"
13.213.68.167 - - [27/Aug/2026:23:07:43 +0000] "GET /rclone.conf HTTP/1.1" 404 3431 "http://solentyachtcharter.com/rclone.conf" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "192.168.225.7"
13.213.68.167 - - [27/Aug/2026:23:07:45 +0000] "GET /.git/HEAD HTTP/1.1" 404 153 "http://solentyachtcharter.com/.git/HEAD" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" "172.30.203.157"
13.213.68.167 - - [27/Aug/2026:23:07:45 +0000] "GET /.aws/credentials HTTP/1.1" 404 3431 "http://solentyachtcharter.com/.aws/cr
...
show less
Web App Attack
🇫🇮
JimArchon72
2026-08-27 22:50:01
(2 weeks ago)
2026/08/27 22:47:16 "GET /wp-admin/ HTTP/2.0"
Web App Attack
🇫🇮
as211431.net
2026-08-27 21:28:54
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇫🇷
dynamix
2026-08-27 21:25:29
(2 weeks ago)
Multiple WAF Violations
Web App Attack
🇩🇪
BlueWire Hosting
2026-08-27 19:51:01
(2 weeks ago)
Aggressive scanning resulting into 404
Bad Web Bot
🇧🇪
voormedia
2026-08-27 15:19:51
(2 weeks ago)
Accessed trap at '/.aws/config'
Web App Attack
🇦🇺
[email protected]
2026-08-27 13:44:42
(2 weeks ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /v1/graphql
Web App Attack
🇳🇱
debestelapp
2026-08-27 13:40:06
(2 weeks ago)
Web App Attack
🇩🇪
LRob
2026-08-27 12:32:50
(2 weeks ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /dist/manifest.json (+3 more) | 2026-08-27 12:32 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-27 12:30:08
(2 weeks ago)
Portscan: TCP/8443 (9x), TCP/8080 (10x), TCP/80, TCP/443
Port Scan
🇩🇪
big-cloud.nl
2026-08-27 12:26:14
(2 weeks ago)
Try to access /config/.env
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-27 12:09:29
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking