๐ณ๐ฑ
homeshowdomain.nl
2026-10-01 21:59:04
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-30.
show less
Web App Attack
SSH
Hacking
๐ง๐ท
radardatelecom
2026-09-30 22:26:05
(3 days ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฉ๐ช
Reinhard
2026-09-30 21:33:06
(3 days ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 15:51:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:51:07.135205 2026] [security2:error] [pid 28004:tid 28004] [client 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d:34890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "havertownopenstudios.com"] [uri "/.git/HEAD"] [unique_id "ar0v62Xm51EVb4VGXOFncgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-30 15:25:00
(3 days ago)
(web_sensitive_file) srv101 Sensitive file probe (.env/.git/backup) 2600:1f18:e5b:c900:ced2:89f9:e12 ...
show more
(web_sensitive_file) srv101 Sensitive file probe (.env/.git/backup) 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:46:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:46:26.654660 2026] [security2:error] [pid 28116:tid 28116] [client 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d:37650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aws.corepest.com"] [uri "/.env.local"] [unique_id "ar0gwop8D48adM20PziPlAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:10:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:10:41.192183 2026] [security2:error] [pid 11327:tid 11327] [client 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d:57264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadkings.biz"] [uri "/.git/HEAD"] [unique_id "ar0YYcPT8SJ9JxoFk-YVbAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:13:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:13:42.798237 2026] [security2:error] [pid 26139:tid 26139] [client 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/app/etc/local.xml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.portfoliolighting.net"] [uri "/app/etc/local.xml"] [unique_id "ar0LBnm7JYR_9SDvx4l1ogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 13:11:58
(3 days ago)
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-07al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d - - [30/Sep/2026:15:11:50 +0200] "GET /kxs-1790773910379169609-nonexistent HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
2600:1f18:e5b:c900:ced2:89f9:e12a:e54d - - [30/Sep/2026:15:11:50 +0200] "GET /.env.local HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
2600:1f18:e5b:c900:ced2:89f9:e12a:e54d - - [30/Sep/2026:15:11:50 +0200] "GET /.env.save HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
2600:1f18:e5b:c900:ced2:89f9:e
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-30 12:53:45
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 12:27:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:27:40.001380 2026] [security2:error] [pid 2384:tid 2397] [client 2600:1f18:e5b:c900:ced2:89f9:e12a:e54d:57746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelmercier.com"] [uri "/.git/HEAD"] [unique_id "ar0APH4ySs98-d2MmCGbMQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-30 12:26:15
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /parameters.yml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
e.fierstra
2026-09-30 11:58:08
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐น
mgarofano80
2026-09-30 10:49:39
(3 days ago)
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-30 10:47:36
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: billing.dont-eat-the-pudding.online | URI: /.env.local | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack