🇧🇬
alnaasd
2026-08-10 13:27:07
(1 month ago)
WAF block action triggered by rule set "Version Control - Information Disclosure" (24 occurrences ob ...
show more
WAF block action triggered by rule set "Version Control - Information Disclosure" (24 occurrences observed).
show less
Web App Attack
🇫🇷
Baking333
2026-08-09 09:58:46
(1 month ago)
[redacted] 34.155.141.128 - - [09/Aug/2026:10:58:44 +0100] "GET /.aws/credentials HTTP/1.1" 302 6783 ...
show more
[redacted] 34.155.141.128 - - [09/Aug/2026:10:58:44 +0100] "GET /.aws/credentials HTTP/1.1" 302 6783 0/41541 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://[redacted]/support/amazonbot)" [redacted] 34.155.141.128 - - [09/Aug/2026:10:58:44 +0100] "GET / HTTP/1.1" 200 8815 0/56863 "https://[redacted]/.aws/credentials" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://[redacted]/support/amazonbot)"
show less
Bad Web Bot
Web App Attack
🇮🇹
ciccio diddo
2026-08-09 07:19:17
(1 month ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-08-09 06:50:28
(1 month ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_server_contact,ndpi_suspicious_entropy
Hacking
🇨🇦
1gz
2026-08-09 05:15:42
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-config.php.bak
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇫🇷
Baking333
2026-08-09 03:43:59
(1 month ago)
[redacted] 34.155.141.128 - - [09/Aug/2026:04:43:57 +0100] "GET /.git/HEAD HTTP/1.1" 302 1584 0/3394 ...
show more
[redacted] 34.155.141.128 - - [09/Aug/2026:04:43:57 +0100] "GET /.git/HEAD HTTP/1.1" 302 1584 0/33943 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://[redacted]/support/amazonbot)" [redacted] 34.155.141.128 - - [09/Aug/2026:04:43:57 +0100] "GET /.git/config HTTP/1.1" 302 6803 0/35007 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://[redacted]/support/amazonbot)"
show less
Bad Web Bot
Web App Attack
🇩🇪
SiyCah
2026-08-09 03:00:02
(1 month ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
🇫🇮
albionfreemarket.com
2026-08-09 02:42:07
(1 month ago)
34.155.141.128 - - [09/Aug/2026:02:42:05 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfree ...
show more
34.155.141.128 - - [09/Aug/2026:02:42:05 +0000] "POST /graphql HTTP/2.0" 403 555 "https://albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "FR"
...
show less
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-08-09 01:29:19
(1 month ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
Zundapper
2026-08-08 23:34:48
(1 month ago)
34.155.141.128 - - [09/Aug/2026:01:34:47 +0200] "GET /signin HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Lin ...
show more
34.155.141.128 - - [09/Aug/2026:01:34:47 +0200] "GET /signin HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.155.141.128 - - [09/Aug/2026:01:34:47 +0200] "GET /auth/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.155.141.128 - - [09/Aug/2026:01:34:47 +0200] "GET /login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.155.141.128 - - [09/Aug/2026:01:34:47 +0200] "GET /admin/login HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
34.155.141.128 - - [09/Aug/2026:01:34:47 +0200] "GET /admin HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
...
show less
Web App Attack
Port Scan
🇩🇪
hbrks
2026-08-08 22:23:02
(1 month ago)
196 attack(s) detected, such as these: {"event":"web_block","ip":"34.155.141.128","host":"www.marche ...
show more
196 attack(s) detected, such as these: {"event":"web_block","ip":"34.155.141.128","host":"www.marche-be.com","request":"GET /my HTTP/2.0","user_agent":"","reason":"Status-404","timestamp":"2026-08-08T22:23:02 00:00","logentry":"www.marche-be.com 34.155.141.128 - - [09/Aug/2026:00:23:02 0200] \"GET /my HTTP/2.0\" 404 555 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36\" \"172.25.79.21:80\""} * Report Details *: https://p4u.xyz/6GZORG5TXAL/1* IP Details *: https://p4u.xyz/6GZORG5TXAL/2
show less
Web Spam
Hacking
Bad Web Bot
🇩🇪
ger-stg-sifi1
2026-08-08 22:17:26
(1 month ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-08 20:19:59
(1 month ago)
[Sat Aug 08 22:19:57.055901 2026] [proxy_fcgi:error] [pid 12295:tid 12405] [client 34.155.141.128:59 ...
show more
[Sat Aug 08 22:19:57.055901 2026] [proxy_fcgi:error] [pid 12295:tid 12405] [client 34.155.141.128:59470] AH01071: Got error 'Primary script unknown'
[Sat Aug 08 22:19:58.575228 2026] [proxy_fcgi:error] [pid 2307:tid 2344] [client 34.155.141.128:59502] AH01071: Got error 'Primary script unknown'
[Sat Aug 08 22:19:58.684357 2026] [proxy_fcgi:error] [pid 12296:tid 12416] [client 34.155.141.128:59492] AH01071: Got error 'Primary script unknown'
[Sat Aug 08 22:19:58.795399 2026] [proxy_fcgi:error] [pid 1614:tid 1787] [client 34.155.141.128:59402] AH01071: Got error 'Primary script unknown'
[Sat Aug 08 22:19:58.796129 2026] [proxy_fcgi:error] [pid 12179:tid 12246] [client 34.155.141.128:59576] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
🇩🇪
hbrks
2026-08-08 12:46:00
(1 month ago)
196 attack(s) detected, such as these: {"event":"web_block","ip":"34.155.141.128","host":"api.marche ...
show more
196 attack(s) detected, such as these: {"event":"web_block","ip":"34.155.141.128","host":"api.marche-be.com","request":"GET /profile HTTP/2.0","user_agent":"","reason":"Status-404","timestamp":"2026-08-08T12:46:00 00:00","logentry":"api.marche-be.com 34.155.141.128 - - [08/Aug/2026:14:46:00 0200] \"GET /profile HTTP/2.0\" 404 0 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36\" \"172.25.79.38:5000\""} * Report Details *: https://p4u.xyz/M4YZTC8QFOS/1* IP Details *: https://p4u.xyz/M4YZTC8QFOS/2
show less
Web Spam
Hacking
Bad Web Bot
🇺🇸
MaxSmartCode
2026-08-08 11:47:02
(1 month ago)
Credential brute-force attacks on webpage.
Brute-Force
SSH