π§πͺ
taivas.nl
2026-09-15 04:32:42
(1 day ago)
Many_bad_calls
Web App Attack
Anonymous
2026-09-14 20:42:15
(1 day ago)
Portscan: TCP/8080 (7x), TCP/8443 (9x)
Port Scan
π©πͺ
findlab
2026-09-14 17:35:01
(1 day ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-14 16:51:35
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
πΊπΈ
Major Hostility
2026-09-14 16:36:48
(1 day ago)
"GET /rclone.conf HTTP/1.1" 404
"GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404
"GET /@ ...
show more
"GET /rclone.conf HTTP/1.1" 404
"GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1" 404
"GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/1.1" 404
"GET /.vite/manifest.json HTTP/1.1" 404
"GET /@fs/var/task/.env?raw?? HTTP/1.1" 404
"GET /admin%2F.env HTTP/1.1" 404
"GET /api%2F.env HTTP/1.1" 404
"GET /dashboard%2F.env HTTP/1.1" 404
"GET /settings%2F.env HTTP/1.1" 404
"GET /@fs/.env?url&raw?? HTTP/1.1" 404
"GET /@fs/.env?import&?raw?? HTTP/1.1" 404
"GET /@fs/.env?raw&url?? HTTP/1.1" 404
show less
Web App Attack
π§πͺ
taivas.nl
2026-09-14 16:32:11
(1 day ago)
Bad_requests
Bad Web Bot
π«π·
Baking333
2026-09-14 16:23:38
(1 day ago)
[redacted] 34.23.22.112 - - [14/Sep/2026:17:02:19 +0100] "GET / HTTP/1.1" 200 9564 0/133224 "https:/ ...
show more
[redacted] 34.23.22.112 - - [14/Sep/2026:17:02:19 +0100] "GET / HTTP/1.1" 200 9564 0/133224 "https://[redacted]/[redacted]" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://[redacted]/)" [redacted] 34.23.22.112 - - [14/Sep/2026:17:02:19 +0100] "GET / HTTP/1.1" 200 9563 0/135985 "https://[redacted]/[redacted]" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 16:17:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.23.22.112 (112.22.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.23.22.112 (112.22.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 12:17:10.309108 2026] [security2:error] [pid 17116:tid 17116] [client 34.23.22.112:57694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||angelsofrhodeisland.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "angelsofrhodeisland.com"] [uri "/z9x8c7v6b5-debug-trigger-angelsofrhodeisland.com"] [unique_id "aqgeBs339XNwG4dsehxBuQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Baking333
2026-09-14 16:02:19
(1 day ago)
[redacted] 34.23.22.112 - - [14/Sep/2026:17:02:17 +0100] "GET /backend/.env HTTP/1.1" 302 6778 0/332 ...
show more
[redacted] 34.23.22.112 - - [14/Sep/2026:17:02:17 +0100] "GET /backend/.env HTTP/1.1" 302 6778 0/33210 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://[redacted]/)" [redacted] 34.23.22.112 - - [14/Sep/2026:17:02:17 +0100] "GET /config/.env HTTP/1.1" 302 6778 0/32720 "-" "CCBot/2.0 (https://[redacted]/faq/)"
show less
Bad Web Bot
Web App Attack
πΊπΈ
1gz
2026-09-14 15:54:44
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /api
UA: Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¦πΊ
[email protected]
2026-09-14 15:47:40
(1 day ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /webpack-stats.json
Web App Attack
π·π΄
clauss
2026-09-14 15:08:01
(1 day ago)
34.23.22.112 - - [14/Sep/2026:18:08:00 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (co ...
show more
34.23.22.112 - - [14/Sep/2026:18:08:00 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
34.23.22.112 - - [14/Sep/2026:18:08:00 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
πΈπ°
KZP
2026-09-14 14:01:16
(1 day ago)
Automatic report from KZP firewall log.
Port Scan
Hacking
Brute-Force
π§πͺ
cmbplf
2026-09-13 01:46:02
(3 days ago)
322 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
πΉπ
thaizone.com
2026-09-12 23:59:32
(3 days ago)
Hacking attempts against websites (D1) #4
Web App Attack
Hacking