๐ฎ๐ณ
evicky2002
2026-08-09 06:00:00
(2 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-08-08 05:13:49
(2 weeks ago)
24 attacks on env grabbing URLs:
GET /storage/.env HTTP/1.1
Hacking
๐ฉ๐ช
Ba-Yu
2026-08-07 13:27:22
(2 weeks ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-08-07 12:00:07
(2 weeks ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-08-07 09:51:47
(2 weeks ago)
Scenarios: http-probing, http-sensitive-files
Total requests: 15
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 08:08:32
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:08:26.830568 2026] [security2:error] [pid 2327939:tid 2327939] [client 2a02:c207:2333:5792::1:48908] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||secemexico.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "secemexico.com"] [uri "/"] [unique_id "anWSem32jC07lOnYpFa4zQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 07:03:42
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:03:35.080139 2026] [security2:error] [pid 2842444:tid 2842444] [client 2a02:c207:2333:5792::1:33078] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||vm-srl.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "vm-srl.com"] [uri "/"] [unique_id "anWDR_5SEHOI3uOYBzNCIwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-07 06:22:05
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ช๐ธ
alferez
2026-08-07 06:13:26
(2 weeks ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-07 06:03:42
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 04:50:10
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:50:04.412305 2026] [security2:error] [pid 1275274:tid 1275274] [client 2a02:c207:2333:5792::1:47994] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dbq.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dbq.us"] [uri "/"] [unique_id "anVj_Mm1Sat-ztzWGUuZ9wAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 04:32:23
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserve ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:c207:2333:5792::1 (vmi3335792.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:32:18.150354 2026] [security2:error] [pid 4115041:tid 4115041] [client 2a02:c207:2333:5792::1:40864] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||dalessalesandservice.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dalessalesandservice.com"] [uri "/"] [unique_id "anVf0opOstfQXh6gzHVG-QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-07 04:31:43
(2 weeks ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /env/.env | 5 distinct paths | UA: Mozilla/5.0 ( ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /env/.env | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
show less
Hacking
๐ฆ๐บ
2000cn.com.au
2026-08-07 04:21:57
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
pinguin
2026-08-07 03:21:18
(2 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /private/.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot