π¬π§
Celtic
2026-08-28 21:24:49
(8 minutes ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
π³π±
e.fierstra
2026-08-28 21:15:11
(17 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©π°
HostingGroup
2026-08-28 20:26:53
(1 hour ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 2. First blocked: 2026-08-28.
show less
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-28 18:46:04
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π«π·
pm33
2026-08-28 18:16:24
(3 hours ago)
Wordpress login attempts
Brute-Force
π©πͺ
LRob
2026-08-28 16:12:13
(5 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wp-config.php~ (+12 more) | 2026-08-28 16:12 UTC
show less
Hacking
Web App Attack
π©πͺ
FeG Deutschland
2026-08-28 15:55:58
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 15:10:28
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.122.254.218 (218.254.122.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.254.218 (218.254.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:10:22.468321 2026] [security2:error] [pid 32713:tid 32713] [client 34.122.254.218:48152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natursac.com"] [uri "/wp-config.php.bak"] [unique_id "apGk3olSmlJS2usQku26GwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
macrob
2026-08-28 15:04:04
(6 hours ago)
2026/08/28 15:04:02 [error] 3672842#3672842: *530476151 access forbidden by rule, client: 34.122.254 ...
show more
2026/08/28 15:04:02 [error] 3672842#3672842: *530476151 access forbidden by rule, client: 34.122.254.218, server: fastcredit.net.ua, request: "GET /.env.old HTTP/2.0", host: "fastcredit.net.ua"
2026/08/28 15:04:02 [error] 3672840#3672840: *530473563 access forbidden by rule, client: 34.122.254.218, server: fastcredit.net.ua, request: "GET /.env.dev HTTP/2.0", host: "fastcredit.net.ua"
2026/08/28 15:04:02 [error] 3672841#3672841: *530473732 access forbidden by rule, client: 34.122.254.218, server: fastcredit.net.ua, request: "GET /.env.local HTTP/2.0", host: "fastcredit.net.ua"
...
show less
Web App Attack
π©πͺ
neckaralb-admin.de
2026-08-28 15:02:39
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π¬π§
pinguin
2026-08-28 13:56:40
(7 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-28 13:35:59
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.122.254.218 (218.254.122.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.122.254.218 (218.254.122.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 09:35:54.193911 2026] [security2:error] [pid 20523:tid 20523] [client 34.122.254.218:58642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rktect.com"] [uri "/wp-config.php~"] [unique_id "apGOuivOxOqvkgOUrbuk-AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
creechy
2026-08-28 13:02:12
(8 hours ago)
34.122.254.218 - - [28/Aug/2026:06:02:04 -0700] "GET /.env.save HTTP/1.1" 404 761
...
Hacking
Bad Web Bot
π©πͺ
4server
2026-08-28 12:53:32
(8 hours ago)
[FriAug2814:53:30.2532882026][security2:error][pid2675475:tid2675489][client34.122.254.218:0]ModSecu ...
show more
[FriAug2814:53:30.2532882026][security2:error][pid2675475:tid2675489][client34.122.254.218:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cnv.wildpferde.ch\"][uri\"/wp-config.php.bak\"][unique_id\"apGEypG8cPgMoTG7mB-QXQAAAAI\"]
show less
Port Scan
Brute-Force
Web App Attack
π¬π§
consul.to
2026-08-28 12:42:26
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack