๐ง๐ฌ
Stoyko Stoykov
2026-07-22 14:28:12
(1 hour ago)
172.71.95.94 - - [22/Jul/2026:17:28:11 +0300] "GET /.aws/credentials HTTP/1.1" 301 162 "-" "Mozilla/ ...
show more
172.71.95.94 - - [22/Jul/2026:17:28:11 +0300] "GET /.aws/credentials HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; U; Linux x86_64; us; rv:1.9.1.19) Gecko/20110430 shadowfox/7.0 (like Firefox/7.0"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-26 19:40:02
(3 weeks ago)
172.71.95.94 - - [26/Jun/2026:21:40:01 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 43 ...
show more
172.71.95.94 - - [26/Jun/2026:21:40:01 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.95.94 - - [26/Jun/2026:21:40:01 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 242 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.95.94 - - [26/Jun/2026:21:40:01 +0200] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.95.94 - - [26/Jun/2026:21:40:01 +0200] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 242 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.71.95.94 - - [26/Jun/2026:21:40:02 +0200] "GET //2018/wp-includes/wlwmanifest.xml HTTP/1.1" 404
...
show less
Brute-Force
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-26 09:59:48
(3 weeks ago)
172.71.95.94 - - [26/Jun/2026:12:59:45 +0300] "GET /mail/.git/config HTTP/1.1" 301 162 "-" "Mozilla/ ...
show more
172.71.95.94 - - [26/Jun/2026:12:59:45 +0300] "GET /mail/.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ต๐ฑ
srebrakowski.com
2026-06-26 02:29:17
(3 weeks ago)
crowdsec/waf-detected-exploits
Brute-Force
๐ต๐ฑ
srebrakowski.com
2026-06-21 17:06:41
(1 month ago)
crowdsec/waf-detected-exploits
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-17 15:50:23
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 11:50:16.887599 2026] [security2:error] [pid 1613:tid 1613] [client 172.71.95.94:10907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgas.com.scottwithers.xyz"] [uri "/.git/config"] [unique_id "ajLCODkmNChKla1P6W2RkwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-16 16:31:10
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 22:44:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:44:36.263247 2026] [security2:error] [pid 6077:tid 6077] [client 172.71.95.94:9880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rgdemos.kmelson.com"] [uri "/.git/config"] [unique_id "aidF1LigVaYA0y7I4jy-5wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 21:50:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:50:39.656679 2026] [security2:error] [pid 7501:tid 7501] [client 172.71.95.94:11134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdn.customdesignsbybjp.com"] [uri "/.git/config"] [unique_id "aic5L3oL9OmQ_peN_WKgegAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-06-08 17:53:05
(1 month ago)
172.71.95.94 - - [08/Jun/2026:20:53:04 +0300] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 ( ...
show more
172.71.95.94 - - [08/Jun/2026:20:53:04 +0300] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 6.1; rv:33.0) Gecko/20100101 Firefox/33.0"
...
show less
Hacking
Web App Attack
๐ฌ๐ง
pinguin
2026-05-30 15:11:33
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-05-29 22:08:11
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-28.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-26 17:41:34
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 13:41:31.123885 2026] [security2:error] [pid 4400:tid 4410] [client 172.71.95.94:12574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realitybytes.us.mailporte.com"] [uri "/.git/config"] [unique_id "ahXbS8T8nlribm3IB9Yh9gAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-26 10:00:28
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-05-25 05:14:20
(1 month ago)
28 attacks on PHP URLs, site downloads, env grabbing URLs, config grabbing URLs (type 2):
GET /confi ...
show more
28 attacks on PHP URLs, site downloads, env grabbing URLs, config grabbing URLs (type 2):
GET /config.php.bak HTTP/1.1
GET /db.sql HTTP/1.1
GET /api/.env HTTP/1.1
GET /config/development.json HTTP/1.1
show less
Web App Attack
Hacking