๐ฉ๐ช
dpsbs
2026-08-15 17:48:24
(1 week ago)
multiple ips intrustions detected
Hacking
๐ฎ๐น
clamehost.it
2026-08-15 16:28:01
(1 week ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ฉ๐ช
LRob
2026-08-15 16:15:45
(1 week ago)
Credential and secrets file probing | req: /.env.bak | UA: Mozilla/5.0 (compatible; Googlebot/2.1; + ...
show more
Credential and secrets file probing | req: /.env.bak | UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Hacking
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-15 16:08:20
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from IT.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from IT.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /app/.env
UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
Andrew
2026-08-15 13:43:03
(1 week ago)
34.17.147.46 - - [15/Aug/2026:14:43:01 +0100] "GET /.git/config HTTP/1.1" 404 5586 "-" "Mozilla/5.0 ...
show more
34.17.147.46 - - [15/Aug/2026:14:43:01 +0100] "GET /.git/config HTTP/1.1" 404 5586 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.17.147.46 - - [15/Aug/2026:14:43:01 +0100] "GET /.gitconfig HTTP/1.1" 404 3669 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.17.147.46 - - [15/Aug/2026:14:43:01 +0100] "GET /.git-credentials HTTP/1.1" 404 5591 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.17.147.46 - - [15/Aug/2026:14:43:01 +0100] "GET /.git/HEAD HTTP/1.1" 404 5584 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.17.147.46 - - [15/Aug/2026:14:43:01 +0100] "GET /.gitlab-ci.yml HTTP/1.1" 404 3673 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
34.17.147.46 - - [15/Aug/2026:14:43:02 +0100] "GET /.github/workflows/deploy.yml HTTP/1.1" 404 3687 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 13:35:26
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 34.17.147.46 (46.147.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.17.147.46 (46.147.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 09:35:19.391133 2026] [security2:error] [pid 2994:tid 2994] [client 34.17.147.46:55446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||live.fairfieldfarms.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "live.fairfieldfarms.net"] [uri "/rclone.conf"] [unique_id "aoBrFxkm0mp2_wscQ32BVQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-08-15 13:11:41
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.17.147.46 (IT/Italy/46.147.17.34.bc.googleus ...
show more
(mod_security) mod_security (id:949110) triggered by 34.17.147.46 (IT/Italy/46.147.17.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
๐ฎ๐น
VHosting
2026-08-15 13:05:03
(1 week ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
nyt
2026-08-15 12:57:49
(1 week ago)
Sensitive File Probe, Request for sensitive file, but returned 404
Web App Attack
๐ซ๐ท
GEDAL
2026-08-15 12:56:53
(1 week ago)
Fail2ban nginx-git @ <hostname> : 34.17.147.46 - - [15/Aug/2026:14:56:52 +0200] "GET /.git/config HT ...
show more
Fail2ban nginx-git @ <hostname> : 34.17.147.46 - - [15/Aug/2026:14:56:52 +0200] "GET /.git/config HTTP/2.0" 301 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
show less
Brute-Force
SSH
๐ฉ๐ช
ghostwarriors
2026-08-15 12:50:28
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-15 12:39:54
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
Octopuce
2026-08-15 12:36:54
(1 week ago)
Aggressive web search of vulnerable pages: /.openclaw/.env /.hermes/.env /config/.env.php /core/.env ...
show more
Aggressive web search of vulnerable pages: /.openclaw/.env /.hermes/.env /config/.env.php /core/.env /laravel/.env ...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-15 12:36:12
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Jochen Pretli
2026-08-15 11:29:14
(1 week ago)
connection to honeypot
Email Spam
Port Scan