๐บ๐ธ
bigscoots.com
2026-07-26 07:47:12
(21 hours ago)
(PERMBLOCK) 18.197.42.170 (DE/Germany/ec2-18-197-42-170.eu-central-1.compute.amazonaws.com) has had ...
show more
(PERMBLOCK) 18.197.42.170 (DE/Germany/ec2-18-197-42-170.eu-central-1.compute.amazonaws.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: 1; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Brute-Force
SSH
๐ซ๐ท
Octopuce
2026-07-26 07:32:23
(21 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ซ๐ท
Zundapper
2026-07-26 07:24:07
(22 hours ago)
18.197.42.170 - - [26/Jul/2026:09:24:04 +0200] "GET /config/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 ...
show more
18.197.42.170 - - [26/Jul/2026:09:24:04 +0200] "GET /config/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
18.197.42.170 - - [26/Jul/2026:09:24:05 +0200] "GET /vendor/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
18.197.42.170 - - [26/Jul/2026:09:24:06 +0200] "GET /bin/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
18.197.42.170 - - [26/Jul/2026:09:24:06 +0200] "GET /temp/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
18.197.42.170 - - [26/Jul/2026:09:24:07 +0200] "GET /logs/.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
Anonymous
2026-07-26 07:10:14
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-26 06:01:09
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.197.42.170 (ec2-18-197-42-170.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 18.197.42.170 (ec2-18-197-42-170.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 02:01:05.914817 2026] [security2:error] [pid 2093276:tid 2093276] [client 18.197.42.170:44786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.meridianranchdrc.org"] [uri "/.git/config"] [unique_id "amWiocjK8sfQ0TqR03syLQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Melle
2026-07-26 05:26:47
(1 day ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 18.197.42.170 triggered 5 event ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 18.197.42.170 triggered 5 events | Detected: 2026-07-26T05:26:46.56963225Z
show less
Web App Attack
Hacking
๐บ๐ธ
MatCat
2026-07-26 04:05:04
(1 day ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
Anonymous
2026-07-26 02:42:06
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-24 06:55:54
(2 days ago)
Triggered Cloudflare WAF (linkMaze) from DE.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from DE.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /firebase-key.json
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
dynamix
2026-07-24 05:54:25
(2 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-07-24 04:35:12
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-24 04:24:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 18.197.42.170 (ec2-18-197-42-170.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 18.197.42.170 (ec2-18-197-42-170.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:24:27.269826 2026] [security2:error] [pid 3026588:tid 3026588] [client 18.197.42.170:54348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mazzaro.com.tr"] [uri "/.git/config"] [unique_id "amLo-7iJeRSXlZr3jqnZQgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-24 04:19:27
(3 days ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐จ๐ญ
backslash
2022-04-29 09:50:15
(4 years ago)
block ruleset bad bot: ignores robots.txt 8010B44F7E78AD8B94C70711C72D11CDE0DAC0F4
Bad Web Bot