๐ฉ๐ช
neckaralb-admin.de
2026-08-27 18:19:06
(29 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 17:11:37
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
cwytech
2026-08-27 15:08:16
(3 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-08-27 14:53:54
(3 hours ago)
WebAttack or semilar from 34.153.151.169
Web App Attack
๐ฉ๐ช
23p02732
2026-08-27 11:46:00
(7 hours ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 10:52:59
(7 hours ago)
Scanner hitting /wp-config.php~ on turn.ara-oman.com (GOOGL-2) โ aaguard
Brute-Force
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-27 10:20:38
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.151.169 (169.151.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.151.169 (169.151.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:20:34.036101 2026] [security2:error] [pid 15135:tid 15135] [client 34.153.151.169:49022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.richardpastor.com.jpastorphotographics.com"] [uri "/wp-config.php.bak"] [unique_id "apAPckvS8CDQzQ4a5DYGogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-27 10:18:20
(8 hours ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env.
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Hazzard
2026-08-27 10:16:15
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-08-27 09:54:55
(8 hours ago)
34.153.151.169 - - [27/Aug/2026:09:54:54 +0000] "GET /.env.old HTTP/1.1" 404 15266 "-" "crusader-wor ...
show more
34.153.151.169 - - [27/Aug/2026:09:54:54 +0000] "GET /.env.old HTTP/1.1" 404 15266 "-" "crusader-worker/1.0" "-"
34.153.151.169 - - [27/Aug/2026:09:54:54 +0000] "GET /.env.example HTTP/1.1" 404 15274 "-" "crusader-worker/1.0" "-"
34.153.151.169 - - [27/Aug/2026:09:54:54 +0000] "GET /.env.backup HTTP/1.1" 404 15272 "-" "crusader-worker/1.0" "-"
34.153.151.169 - - [27/Aug/2026:09:54:54 +0000] "GET /.env.bak HTTP/1.1" 404 15266 "-" "crusader-worker/1.0" "-"
34.153.151.169 - - [27/Aug/2026:09:54:54 +0000] "GET /.env.production HTTP/1.1" 404 15280 "-" "crusader-worker/1.0" "-"
...
show less
Port Scan
Brute-Force
Anonymous
2026-08-27 09:08:00
(9 hours ago)
[27/Aug/2026:19:07:59 +1000] "GET /.env.dev HTTP/1.1" 404 236 "crusader-worker/1.0" [27/Aug/2026:19: ...
show more
[27/Aug/2026:19:07:59 +1000] "GET /.env.dev HTTP/1.1" 404 236 "crusader-worker/1.0" [27/Aug/2026:19:07:59 +1000] "GET /storage/logs/laravel.log HTTP/1.1" 404 236 "crusader-worker/1.0"
show less
Hacking
Web App Attack
๐ฆ๐บ
Proxay Fox
2026-08-27 08:07:52
(10 hours ago)
34.153.151.169 - - [27/Aug/2026:18:07:50 +1000] "GET /.env.example HTTP/1.1" 404 1638 "-" "crusader- ...
show more
34.153.151.169 - - [27/Aug/2026:18:07:50 +1000] "GET /.env.example HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 103 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . cf24705070893407c1e27a9d8bc12788e742046318db25c3be7edd88a1e7c068
34.153.151.169 - - [27/Aug/2026:18:07:50 +1000] "GET /.env.prod HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 100 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . 467775a9012c885d85edd8724316f40b9a19b747a66062f3da63b711a4894322
34.153.151.169 - - [27/Aug/2026:18:07:50 +1000] "GET /wp-config.php.bak HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 108 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . 067224f5c22652f911178e77288e834cd5b7c44fac46e7680b7e2a1228c58e23
34.153.151.169 - - [27/Aug/2026:18:07:50 +1000] "GET /.env.local HTTP/1.1" 404 1638 "-" "crusader-worker/1.0" "-" 101 2665 TLSv1.3/TLS_AES_256_GCM_SHA384 . 1cd91ce0fc20477c5f810eac9c05791ab24b4fb8cdfbcdbf909aad811755a9e1
34.153.151.169 - - [27/Aug/2026:18:07:50 +1000] "GET /actuator/configprops HTTP/1.1" 404 1638 "-" "crusa
...
show less
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-08-27 08:01:14
(10 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
netclix.gr
2026-08-27 08:00:06
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.153.151.169 (GB/United Kingdom/169.1 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.153.151.169 (GB/United Kingdom/169.151.153.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ณ๐ฑ
alferez
2026-08-27 07:02:44
(11 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack