๐ณ๐ฑ
homeshowdomain.nl
2026-10-03 21:59:57
(15 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-02.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
arsonist
2026-10-02 20:36:52
(1 day ago)
[fail2ban]
2026-10-02T20:36:52.485455+00:00 arson caddy[1712]: {"level":"info","ts":1790973412.48542 ...
show more
[fail2ban]
2026-10-02T20:36:52.485455+00:00 arson caddy[1712]: {"level":"info","ts":1790973412.4854293,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"2400:6180:10:200::e6b7:c000","remote_port":"7400","client_ip":"2400:6180:10:200::e6b7:c000","proto":"HTTP/2.0","method":"GET","host":"ask.possum.city","uri":"/.env","headers":{"Accept-Encoding":["gzip, br, deflate"],"Accept":["*/*"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"ask.possum.city","ech":false}},"bytes_read":0,"user_id":"","duration":0.0000745,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
Anonymous
2026-10-02 19:28:34
(1 day ago)
2400:6180:10:200::e6b7:c000 - - [02/Oct/2026:19:28:33 +0000] "GET /.env HTTP/2.0" 404 663 "-" "Mozil ...
show more
2400:6180:10:200::e6b7:c000 - - [02/Oct/2026:19:28:33 +0000] "GET /.env HTTP/2.0" 404 663 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hary74656
2026-10-02 18:31:44
(1 day ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
sg "Inbo ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
sg "Inbound Anomaly Score Exceeded (Total Score: 30)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "aschi.at"] [uri "/wp-content/plugins/lws-affiliation/view/admin/preview_widget.php"] [unique_id "ar_4kEuNPGiJ0pGjQPXAyAAATw4"]
[Fri Oct 02 20:31:44.303888 2026] [vhost aschi.at] [security2:error] [pid 593438:tid 140399592376000] [client 2400:6180:10:200::e6b7:c000:21768] [realclient 2400:6180:10:200::e6b7:c000:21768] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 30)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "aschi.at"] [uri "/wp-content/plugins/canto/includes/lib/sizes.php"] [unique_id "ar_4kEuNPGiJ0pGjQPXAxwAATwI"]
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2026-10-02 17:29:02
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from AU.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
ipoac.nl
2026-10-02 17:28:49
(1 day ago)
-:443 2400:6180:10:200::e6b7:c000 - - [02/Oct/2026:19:28:48 +0200] - "GET /.git/config HTTP/2.0" 404 ...
show more
-:443 2400:6180:10:200::e6b7:c000 - - [02/Oct/2026:19:28:48 +0200] - "GET /.git/config HTTP/2.0" 404 2005 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐ณ๐ฑ
Mangelot Hosting
2026-10-02 17:10:12
(1 day ago)
(modsec_attack) srv102 ModSecurity attack 2400:6180:10:200::e6b7:c000 (AU/Australia/-): 3 in the las ...
show more
(modsec_attack) srv102 ModSecurity attack 2400:6180:10:200::e6b7:c000 (AU/Australia/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-02 16:46:52
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:38:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:38:43.791163 2026] [security2:error] [pid 9828:tid 9828] [client 2400:6180:10:200::e6b7:c000:26986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artspacecleveland.org"] [uri "/.env"] [unique_id "ar_eE3MOfr2xvVNLDEd2FQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-02 16:23:11
(1 day ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 16:19:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:19:39.378350 2026] [security2:error] [pid 23449:tid 23449] [client 2400:6180:10:200::e6b7:c000:30364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artocratic.com"] [uri "/.env"] [unique_id "ar_ZmyDZ_BS0De2OxphU2wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 16:04:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:04:22.883059 2026] [security2:error] [pid 7849:tid 7849] [client 2400:6180:10:200::e6b7:c000:64890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artisticheadstones.com"] [uri "/.env"] [unique_id "ar_WBqY_xH2E5KWXUVhF2AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:42:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:42:28.585277 2026] [security2:error] [pid 25489:tid 25489] [client 2400:6180:10:200::e6b7:c000:11658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "articulaterecords.com"] [uri "/.env"] [unique_id "ar_Q5Gsi5fkXiXD9472OyQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 15:32:24
(1 day ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2400:6180:10:200::e6b7:c000 - - [02/Oct/2026:17:32:08 +0200] "GET /praktijk/medische-training-en-fitness/.git/config HTTP/2.0" 301 73 "https://arthron.nl/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:24:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:6180:10:200::e6b7:c000 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:24:29.367398 2026] [security2:error] [pid 19647:tid 19647] [client 2400:6180:10:200::e6b7:c000:16696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artfranz.com"] [uri "/.env"] [unique_id "ar_MrbAiQOGSKQ14z9nZQAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack