🇫🇷
spot
2026-09-06 05:57:41
(13 hours ago)
185.198.243.127 - - [06/Sep/2026:06:57:40 +0100] "GET /private/.env HTTP/1.1" 404 522 "-" "Mozilla/5 ...
show more
185.198.243.127 - - [06/Sep/2026:06:57:40 +0100] "GET /private/.env HTTP/1.1" 404 522 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.36"
...
show less
Web App Attack
VPN IP
🇫🇷
ISPLtd
2026-09-06 04:45:49
(14 hours ago)
185.198.243.127 [06/Sep/2026:01:45:48 -0300] 178.18.241.253:80 URL:/application/.env "GET /applicati ...
show more
185.198.243.127 [06/Sep/2026:01:45:48 -0300] 178.18.241.253:80 URL:/application/.env "GET /application/.env
185.198.243.127 [06/Sep/2026:01:45:48 -0300] 178.18.241.253:80 URL:/.env.project "GET /.env.project%20
...
show less
Hacking
Web App Attack
Anonymous
2026-09-04 17:27:34
(2 days ago)
Attempted search for exploits and vulnerabilities detected by fail2ban
...
Port Scan
Brute-Force
🇺🇸
masterguru
2026-07-10 04:19:04
(1 month ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-169)
show less
Bad Web Bot
🇲🇾
Rizzy
2026-07-09 15:59:33
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-07-09 03:11:04
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
Lino Project
2026-07-08 17:42:18
(1 month ago)
185.198.243.127 - - [08/Jul/2026:19:42:17 +0200] "GET /000.php HTTP/2.0" 404 135656 "https://primobi ...
show more
185.198.243.127 - - [08/Jul/2026:19:42:17 +0200] "GET /000.php HTTP/2.0" 404 135656 "https://primobio.it/000.php" "Go-http-client/2.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-10 20:50:21
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 185.198.243.127 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.198.243.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 16:50:16.201448 2026] [security2:error] [pid 655922:tid 655922] [client 185.198.243.127:34525] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.applemaccomputerconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.applemaccomputerconsulting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adliiEypf9TX4_gURKUoaAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-03-14 20:47:03
(5 months ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
mrcrassi
2026-03-13 00:03:57
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
kosada.com
2026-02-10 23:27:30
(6 months ago)
Web vulnerability probing: /.well-known/acme-challenge/wp-login.php
Web App Attack
🇫🇷
dynamix
2026-02-10 20:41:41
(6 months ago)
Multiple WAF Violations
Web App Attack
🇬🇧
pinguin
2026-02-03 09:36:12
(7 months ago)
Triggered Cloudflare WAF (linkMaze) from GB.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD ...
show more
Triggered Cloudflare WAF (linkMaze) from GB.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (HEAD method)
Endpoint: /backup/public_html.rar
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2025-12-16 06:12:27
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 185.198.243.127 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.198.243.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 01:12:21.478237 2025] [security2:error] [pid 23484:tid 23484] [client 185.198.243.127:37377] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "48consultancy.com"] [uri "/.env"] [unique_id "aUD4RZMFRzVfNAjPi-NqdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2025-12-16 05:10:17
(8 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot