๐จ๐ญ
TheCoon
2026-07-28 01:15:01
(1 day ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:01:32
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-26.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
Octopuce
2026-07-27 19:01:03
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-27 16:54:36
(1 day ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:41:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:41:54.309686 2026] [security2:error] [pid 20096:tid 20096] [client 34.228.142.241:47640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sedemo.xyz"] [uri "/.git/config"] [unique_id "amd8Qp_na8FwOXtOu7psuAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 14:07:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:07:04.856726 2026] [security2:error] [pid 8355:tid 8355] [client 34.228.142.241:53528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "securityzonepr.com"] [uri "/.git/config"] [unique_id "amdmCNxiXWLd-Bq1v7gsWwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 13:33:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:33:08.612878 2026] [security2:error] [pid 1931914:tid 1931914] [client 34.228.142.241:50078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "securitymontana.com"] [uri "/.git/config"] [unique_id "amdeFIRVNH3w2JEMvVD5yQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
realstuffie
2026-07-27 13:19:05
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐บ๐ธ
FreeMyIP
2026-07-27 12:32:57
(1 day ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-27 12:18:35
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
nyt
2026-07-27 11:01:50
(1 day ago)
Sensitive File Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:36:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:36:06.295288 2026] [security2:error] [pid 864158:tid 864158] [client 34.228.142.241:50544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secureonebank.net"] [uri "/.git/config"] [unique_id "amcYdkFHuafCFiUTtYlCmwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 04:58:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 34.228.142.241 (ec2-34-228-142-241.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:58:32.028562 2026] [security2:error] [pid 1831109:tid 1831117] [client 34.228.142.241:40548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secure.vnbcares.com"] [uri "/.git/config"] [unique_id "ambleKnEj5agjtJ_4uj5EgAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 10:05:30
(2 days ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (41/60 min)'; Requests=41
Port Scan
๐ซ๐ท
dynamix
2026-07-26 08:34:35
(2 days ago)
Multiple WAF Violations
Web App Attack