๐ฉ๐ช
MBombeck
2026-08-30 06:01:07
(2 days ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-29 21:59:58
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-28.
show less
Web App Attack
SSH
Hacking
๐ฟ๐ฆ
conure.sh
2026-08-29 12:01:52
(3 days ago)
csagent: score 20.8: 404 noise floor x3, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:18:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.142.250 (250.142.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.142.250 (250.142.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:18:16.924421 2026] [security2:error] [pid 12257:tid 12257] [client 34.181.142.250:49334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drwolberg.com"] [uri "/wp-config.php.bak"] [unique_id "apJBaFIGVz8jyYvKtAoO3AAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-08-29 01:52:06
(3 days ago)
Web attack. 34.181.142.250 - - [29/Aug/2026:03:52:05 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 27 ...
show more
Web attack. 34.181.142.250 - - [29/Aug/2026:03:52:05 +0200] "GET /wp-config.php.swp HTTP/1.1" 404 27 "-" "crusader-worker/1.0"
34.181.142.250 - - [29/Aug/2026:03:52:05 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 27 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ฉ๐ช
MBombeck
2026-08-29 00:18:31
(3 days ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-28 23:50:17
(3 days ago)
Web App Attack
๐ฉ๐ช
Nevermind
2026-08-28 23:25:55
(3 days ago)
34.181.142.250 - - [29/Aug/2026:01:25:55 +0200] "GET /.env.production HTTP/1.1" 403 5673 "-" "crusad ...
show more
34.181.142.250 - - [29/Aug/2026:01:25:55 +0200] "GET /.env.production HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
34.181.142.250 - - [29/Aug/2026:01:25:55 +0200] "GET /wp-config.php~ HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
34.181.142.250 - - [29/Aug/2026:01:25:55 +0200] "GET /wp-config.php.swp HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
34.181.142.250 - - [29/Aug/2026:01:25:55 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 5673 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฌ๐ง
pinguin
2026-08-28 22:58:00
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.swp
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 20:52:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.142.250 (250.142.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.142.250 (250.142.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:52:46.263654 2026] [security2:error] [pid 29596:tid 29596] [client 34.181.142.250:58512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dcmillerjr.com"] [uri "/.env.dev"] [unique_id "apH1Hn_5h1DTPDgrVZKMxwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-08-28 19:52:46
(3 days ago)
$f2bV_matches
Hacking
Brute-Force
๐ธ๐ช
vaia.cloud
2026-08-28 18:45:52
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:39:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.142.250 (250.142.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.142.250 (250.142.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:39:39.590753 2026] [security2:error] [pid 11178:tid 11266] [client 34.181.142.250:32822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.plasticsurgeryjournal.aafm.us"] [uri "/.env.prod"] [unique_id "apHV6_S5qDu8MJf3feSHNQAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 18:25:09
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-08-28 18:08:54
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.181.142.250 (US/United States/250.14 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.181.142.250 (US/United States/250.142.181.34.bc.googleusercontent.com)
show less
SQL Injection