🇺🇸
TPI-Abuse
2026-09-07 09:51:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.171.22.178 (ec2-16-171-22-178.eu-north-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 16.171.22.178 (ec2-16-171-22-178.eu-north-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:51:04.964442 2026] [security2:error] [pid 24289:tid 24289] [client 16.171.22.178:55156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcbrude.com"] [uri "/.git/config"] [unique_id "ap6JCHcVlrVBIvqCj0ytDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 09:50:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇭🇺
kranem
2026-09-07 09:00:01
(1 day ago)
Triggered Cloudflare WAF from SE.
Action taken: BLOCK
ASN: 16509 (Amazon.com, Inc.)
Protocol: HTTP/2 ...
show more
Triggered Cloudflare WAF from SE.
Action taken: BLOCK
ASN: 16509 (Amazon.com, Inc.)
Protocol: HTTP/2 (GET method)
Endpoint: /.pem
Timestamp: 2026-09-07T08:56:44Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
show less
Bad Web Bot
🇵🇱
sefinek.net
2026-09-07 08:35:34
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from SE.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /ssl.key | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇵🇱
sledzik1984
2026-09-07 08:33:36
(1 day ago)
2026/09/07 10:33:35 [error] 3011399#3011399: *197902 directory index of "/home/cmapl/transactions/" ...
show more
2026/09/07 10:33:35 [error] 3011399#3011399: *197902 directory index of "/home/cmapl/transactions/" is forbidden, client: 16.171.22.178, server: cma.pl, request: "GET /transactions/ HTTP/1.1", host: "cma.pl"
2026/09/07 10:33:35 [error] 3011399#3011399: *197907 directory index of "/home/cmapl/kardio_faces/" is forbidden, client: 16.171.22.178, server: cma.pl, request: "GET /kardio_faces/ HTTP/1.1", host: "cma.pl"
2026/09/07 10:33:35 [error] 3011399#3011399: *197911 directory index of "/home/cmapl/newevent/" is forbidden, client: 16.171.22.178, server: cma.pl, request: "GET /newevent/ HTTP/1.1", host: "cma.pl"
...
show less
Web App Attack
🇬🇧
Mendip_Defender
2026-09-07 07:33:43
(1 day ago)
16.171.22.178 - - [07/Sep/2026:08:33:53 +0100] "GET /robots.txt HTTP/1.1" 404 1227 "-" "Mozilla/5.0 ...
show more
16.171.22.178 - - [07/Sep/2026:08:33:53 +0100] "GET /robots.txt HTTP/1.1" 404 1227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
16.171.22.178 - - [07/Sep/2026:08:33:53 +0100] "GET /.well-known/jwks.json HTTP/1.1" 404 1227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
16.171.22.178 - - [07/Sep/2026:08:33:55 +0100] "GET /_next/static/buildId.txt HTTP/1.1" 404 1227 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
Web App Attack
🇵🇱
Budyn
2026-09-07 07:21:15
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sql.astropot.website | URI: /.well-known/openid-configuration | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-09-07 07:01:45
(1 day ago)
Web App Attack
🇺🇸
WizardsToolkit
2026-09-07 04:59:14
(1 day ago)
tried to access forbidden files; attempted to access /app/.env
Web App Attack