Anonymous
2026-10-02 18:40:05
(18 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ง๐ช
boxed-it
2026-10-02 18:33:28
(18 hours ago)
GET /%2eenv (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
๐ซ๐ท
COMAITE
2026-10-02 17:08:16
(20 hours ago)
Suspicious URL access.
Web App Attack
Anonymous
2026-10-02 15:00:11
(22 hours ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-10-02 14:00:30
(23 hours ago)
194.127.165.158 - - [02/Oct/2026:15:58:15 +0200] "GET /.git/HEAD HTTP/1.1" 200 23 "-" "find-files/1. ...
show more
194.127.165.158 - - [02/Oct/2026:15:58:15 +0200] "GET /.git/HEAD HTTP/1.1" 200 23 "-" "find-files/1.0" "GB" "City of London" "51.51640" "-0.09300"
194.127.165.158 - - [02/Oct/2026:15:58:15 +0200] "GET /.env.production HTTP/1.1" 404 146 "-" "find-files/1.0" "GB" "City of London" "51.51640" "-0.09300"
194.127.165.158 - - [02/Oct/2026:15:58:15 +0200] "GET /.env.bak HTTP/1.1" 404 146 "-" "find-files/1.0" "GB" "City of London" "51.51640" "-0.09300"
194.127.165.158 - - [02/Oct/2026:15:58:15 +0200] "GET /.env HTTP/1.1" 404 146 "-" "find-files/1.0" "GB" "City of London" "51.51640" "-0.09300"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-02 13:29:22
(23 hours ago)
194.127.165.158 - - [02/Oct/2026:09:29:21 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 40477 "-" "find-fil ...
show more
194.127.165.158 - - [02/Oct/2026:09:29:21 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 40477 "-" "find-files/1.0"
194.127.165.158 - - [02/Oct/2026:09:29:21 -0400] "GET /.env HTTP/1.1" 404 40477 "-" "find-files/1.0"
194.127.165.158 - - [02/Oct/2026:09:29:21 -0400] "GET /.git/config HTTP/1.1" 404 40477 "-" "find-files/1.0"
...
show less
Web App Attack
๐บ๐ธ
H24
2026-10-02 11:47:02
(1 day ago)
/wp-config.php /wp-config.php.save /.aws/credentials
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-02 10:35:18
(1 day ago)
194.127.165.158 - - [02/Oct/2026:06:35:09 -0400] "GET /phpinfo.php HTTP/1.1" 301 4869 "-" "find-file ...
show more
194.127.165.158 - - [02/Oct/2026:06:35:09 -0400] "GET /phpinfo.php HTTP/1.1" 301 4869 "-" "find-files/1.0"
194.127.165.158 - - [02/Oct/2026:06:35:09 -0400] "GET /.git/config HTTP/1.1" 301 4869 "-" "find-files/1.0"
194.127.165.158 - - [02/Oct/2026:06:35:09 -0400] "GET /.aws/credentials HTTP/1.1" 301 4874 "-" "find-files/1.0"
...
show less
Web App Attack
Anonymous
2026-10-02 10:22:41
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-02 10:19:16
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, git_exposure, dotfile_probe, aws_creds, credential_file, ssh_keys, config_backup. Observed by 1 sensor(s); 38 hits.
show less
Web App Attack
๐บ๐ธ
1gz
2026-10-02 10:11:09
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.bak
UA: find-files/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 09:56:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.127.165.158 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 194.127.165.158 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:56:10.684389 2026] [security2:error] [pid 6543:tid 6543] [client 194.127.165.158:56694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siragusafamily.com"] [uri "/wp-config.php.save"] [unique_id "ar9_uoZhy_7k-RcUbMzIVAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-10-02 09:02:12
(1 day ago)
Bad_requests
Bad Web Bot
Anonymous
2026-10-02 08:19:02
(1 day ago)
Bot / scanning and/or hacking attempts: GET /wp-config.php HTTP/1.1, GET /.htaccess HTTP/1.1, GET /. ...
show more
Bot / scanning and/or hacking attempts: GET /wp-config.php HTTP/1.1, GET /.htaccess HTTP/1.1, GET /.env.local HTTP/1.1, GET /config.php HTTP/1.1, GET /application.yml HTTP/1.1, GET /terraform.tfstate HTTP/1.1, GET /.ssh/id_ed25519 HTTP/1.1, GET /wp-config.php.old HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-10-01 17:42:46
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking