๐บ๐ธ
Major Hostility
2025-11-10 14:36:07
(9 months ago)
"GET /xmlrpc.php HTTP/1.1" 403
"GET /api/config HTTP/1.1" 404
"GET /api/settings HTTP/1.1" 404
"GET ...
show more
"GET /xmlrpc.php HTTP/1.1" 403
"GET /api/config HTTP/1.1" 404
"GET /api/settings HTTP/1.1" 404
"GET /config.json HTTP/1.1" 404
"GET /settings.json HTTP/1.1" 404
"GET /app-config.json HTTP/1.1" 404
show less
Web App Attack
๐ฌ๐ง
Mendip_Defender
2025-11-10 02:46:24
(9 months ago)
2602:fa59:9:1c2::1 - - [10/Nov/2025:02:46:06 +0000] "GET /xmlrpc.php HTTP/1.1" 403 146 "-" "python-h ...
show more
2602:fa59:9:1c2::1 - - [10/Nov/2025:02:46:06 +0000] "GET /xmlrpc.php HTTP/1.1" 403 146 "-" "python-httpx/0.28.1"
2602:fa59:9:1c2::1 - - [10/Nov/2025:02:46:14 +0000] "GET /config.json HTTP/1.0" 404 46446 "-" "python-httpx/0.28.1"
2602:fa59:9:1c2::1 - - [10/Nov/2025:02:46:15 +0000] "GET /app-config.json HTTP/1.0" 404 46446 "-" "python-httpx/0.28.1"
...
show less
Hacking
Web App Attack
๐ฎ๐น
ciccio diddo
2025-11-10 02:18:32
(9 months ago)
CMS/WP Exploit xmlrpc port:Tcp/80,443
Brute-Force
Web App Attack
๐ท๐บ
Reaper
2025-11-09 07:47:03
(9 months ago)
Repeated 404 errors from 2602:fa59:9:1c2::1
Web App Attack
๐ฉ๐ฐ
swrlly
2025-11-09 06:43:10
(9 months ago)
1 unauthorized webserver connection
Web App Attack
๐ณ๐ฑ
Site.eu
2025-11-09 04:36:08
(9 months ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
conseilgouz
2025-11-07 18:42:47
(10 months ago)
doe-17 : Block hidden directories=>/.env(/)
Hacking
๐ฉ๐ช
conseilgouz
2025-11-07 13:36:09
(10 months ago)
ece-17 : Block hidden directories=>/.env(/)
Hacking
๐ฌ๐ง
Swiptly
2025-11-06 23:52:03
(10 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐ฉ๐ช
Skyrider
2025-11-06 22:50:55
(10 months ago)
2602:fa59:9:1c2::1 - - [06/Nov/2025:23:50:53 +0100] "GET /api/config HTTP/2.0" 404 114 "-" "python-h ...
show more
2602:fa59:9:1c2::1 - - [06/Nov/2025:23:50:53 +0100] "GET /api/config HTTP/2.0" 404 114 "-" "python-httpx/0.28.1"
2602:fa59:9:1c2::1 - - [06/Nov/2025:23:50:53 +0100] "GET /api/settings HTTP/2.0" 404 114 "-" "python-httpx/0.28.1"
2602:fa59:9:1c2::1 - - [06/Nov/2025:23:50:54 +0100] "GET /.env HTTP/2.0" 404 114 "-" "python-httpx/0.28.1"
2602:fa59:9:1c2::1 - - [06/Nov/2025:23:50:55 +0100] "GET /config.json HTTP/2.0" 404 114 "-" "python-httpx/0.28.1"
2602:fa59:9:1c2::1 - - [06/Nov/2025:23:50:55 +0100] "GET /settings.json HTTP/2.0" 404 114 "-" "python-httpx/0.28.1"
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2025-11-06 12:50:19
(10 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /config.js
UA: python-httpx/0.28.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ฎ
cycastic
2025-11-06 06:34:02
(10 months ago)
Probed /.env on 11/06/2025 06:31:36 +00:00 (UA: python-httpx/0.28.1, Query: )
Web App Attack
๐ฌ๐ง
[email protected]
2025-11-06 00:55:45
(10 months ago)
...
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-11-05 23:52:31
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:9:1c2::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:9:1c2::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 18:52:25.785538 2025] [security2:error] [pid 17567:tid 17567] [client 2602:fa59:9:1c2::1:59596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dadlounge.com"] [uri "/.env"] [unique_id "aQvjOfenhfsk9tg-43Q61QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-05 22:51:51
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:9:1c2::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:9:1c2::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 17:51:44.980398 2025] [security2:error] [pid 12955:tid 12955] [client 2602:fa59:9:1c2::1:60719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "decroos.org"] [uri "/.env"] [unique_id "aQvVACHaJ520d-e3tY2xZQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack