Anonymous
2026-08-08 12:02:06
(3 weeks ago)
Web attack
Bad Web Bot
Web App Attack
🇩🇪
klaus_ph
2026-08-08 11:36:51
(3 weeks ago)
...
Bad Web Bot
🇮🇳
evicky2002
2026-08-08 06:00:00
(3 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇧🇪
cmbplf
2026-08-07 21:17:49
(3 weeks ago)
2.200 requests from abuseipdb.com blacklisted IP (1yr6mos2w)
Brute-Force
Bad Web Bot
🇵🇱
sefinek.net
2026-08-07 21:02:35
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /_debugbar/open | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
Skyrider
2026-08-07 20:13:06
(3 weeks ago)
crowdsecurity/http-sensitive-files
Web App Attack
🇺🇸
Charlesiv
2026-08-07 20:01:24
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /health
Timestamp: 2026-08-07T18:25:47Z
Ray ID: a278536fdbe74e13
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)
show less
Bad Web Bot
🇫🇮
oh.mg
2026-08-07 19:53:29
(3 weeks ago)
[Fri Aug 07 21:53:28.454580 2026] [security2:error] [pid 1151573:tid 1151592] [client 34.180.83.22:0 ...
show more
[Fri Aug 07 21:53:28.454580 2026] [security2:error] [pid 1151573:tid 1151592] [client 34.180.83.22:0] [client 34.180.83.22] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "api.mmn.ca"] [uri "/.aws/config"] [unique_id "anY3uMyFJhDQZBTGCv7U9gAAAA0"]
[Fri Aug 07 21:53:28.508573 2026] [security2:error] [pid 1151573:tid 1151603] [client 34.180.83.22:0] [client 34.180.83.22] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-
...
show less
Web App Attack
Bad Web Bot
🇩🇪
pscriptos
2026-08-07 19:35:12
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-07 19:30:21
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 34.180.83.22 (22.83.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.180.83.22 (22.83.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 15:30:03.824969 2026] [security2:error] [pid 2429749:tid 2429749] [client 34.180.83.22:44346] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "joyannejeffery.net"] [uri "/.git/HEAD"] [unique_id "anYyO8FGC65mYdRXnkKM4wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-07 19:17:04
(3 weeks ago)
Restricted File Access Attempt. Matched phrase ".gitlab-ci.yml" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
MatCat
2026-08-07 19:05:05
(3 weeks ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
🇦🇺
electronico
2026-08-07 19:02:05
(3 weeks ago)
34.180.83.22 - - [08/Aug/2026:06:02:04 +1100] "GET /bootstrap.properties HTTP/2.0" 404 1890 "-" "Moz ...
show more
34.180.83.22 - - [08/Aug/2026:06:02:04 +1100] "GET /bootstrap.properties HTTP/2.0" 404 1890 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
34.180.83.22 - - [08/Aug/2026:06:02:04 +1100] "GET /config/secrets.yml HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
34.180.83.22 - - [08/Aug/2026:06:02:04 +1100] "GET /actuator/env HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
34.180.83.22 - - [08/Aug/2026:06:02:04 +1100] "GET /assets/manifest.json HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
34.180.83.22 - - [08/Aug/2026:06:02:04 +1100] "GET /z9x8c7v6b5-debug-trigger-ip79.ip-51-161-148.net HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
34.180.83.22 - - [08/Aug/2026:06:02:04 +1100] "GET /gradle.properties HTTP/2.0" 404 1854 "-" "Mozilla/5.0 (co
...
show less
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-08-07 18:56:27
(3 weeks ago)
csagent: score 21.2: 404 noise floor x5, secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇸🇬
ipidentify
2026-08-07 18:46:19
(3 weeks ago)
2026-08-07T18:46:22Z GET /config.env
2026-08-07T18:46:22Z GET /frontend/.env
2026-08-07T18:46:22Z GE ...
show more
2026-08-07T18:46:22Z GET /config.env
2026-08-07T18:46:22Z GET /frontend/.env
2026-08-07T18:46:22Z GET /app/.env
2026-08-07T18:46:22Z GET /sendgrid.env
2026-08-07T18:46:22Z GET /production/.env
2026-08-07T18:46:22Z GET /dev/.env
2026-08-07T18:46:22Z GET /docker/.env
2026-08-07T18:46:22Z GET /staging/.env
2026-08-07T18:46:22Z GET /@fs/.env
2026-08-07T18:46:22Z GET /@fs/root/.env
show less
Web App Attack