๐ฎ๐ณ
evicky2002
2026-08-31 00:01:03
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฟ๐ฆ
conure.sh
2026-08-29 12:01:43
(3 days ago)
csagent: score 20.0: secrets grab x1, wp-config backup grab x1; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ช
maxpower
2026-08-29 01:46:47
(3 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.148.228.1 (US/United States/1.228.148.34.bc ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.148.228.1 (US/United States/1.228.148.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/29 03:46:46 [error] 1941220#1941220: *884507 access forbidden by rule, client: 34.148.228.1, server: pescarafestival.it, request: "GET /wp-config.php.swp HTTP/1.1", host: "www.pescarafestival.it"
2026/08/29 03:46:46 [error] 1941213#1941213: *884504 access forbidden by rule, client: 34.148.228.1, server: pescarafestival.it, request: "GET /wp-config.php.bak HTTP/1.1", host: "www.pescarafestival.it"
2026/08/29 03:46:46 [error] 1941220#1941220: *884508 access forbidden by rule, client: 34.148.228.1, server: pescarafestival.it, request: "GET /wp-config.php~ HTTP/1.1", host: "www.pescarafestival.it"
show less
Port Scan
๐ฉ๐ช
Bedios GmbH
2026-08-29 01:23:11
(3 days ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 01:00:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.228.1 (1.228.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.228.1 (1.228.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:00:23.633859 2026] [security2:error] [pid 14533:tid 14533] [client 34.148.228.1:56440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.unwaved.kooroshvaziri.com"] [uri "/.env.local"] [unique_id "apIvJ8AATfZeiBopUrhP8AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 00:50:03
(3 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
1gz
2026-08-28 23:02:56
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.swp
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Sรฉfora Srl
2026-08-28 21:35:26
(3 days ago)
crowdsecurity/http-sensitive-files detected by CrowdSec
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:47:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.228.1 (1.228.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.228.1 (1.228.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:47:44.741210 2026] [security2:error] [pid 7039:tid 7039] [client 34.148.228.1:60916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "museum.henning.org"] [uri "/.env"] [unique_id "apHl4MJOKCf84SNWFlW10QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:25:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.228.1 (1.228.148.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.228.1 (1.228.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:25:35.524993 2026] [security2:error] [pid 13233:tid 13245] [client 34.148.228.1:59936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saryatech.pershia.net"] [uri "/wp-config.php.swp"] [unique_id "apHgr0XeHV8qeP7eYbGIHAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-28 19:10:04
(3 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-28 19:08:02
(3 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-28 18:45:42
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-08-28 17:56:14
(3 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
doll.gl
2026-08-28 17:50:36
(3 days ago)
34.148.228.1 - - [28/Aug/2026:17:50:33 +0000] "GET /wp-config.php.bak HTTP/1.1" 404 162 "-" "crusade ...
show more
34.148.228.1 - - [28/Aug/2026:17:50:33 +0000] "GET /wp-config.php.bak HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack