๐ฉ๐ช
sdos.es
2026-09-16 05:36:13
(6 hours ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:52
(6 hours ago)
309 attacks on password/key grabbing URLs, PHP URLs, env grabbing URLs (type 2), VC URLs, directory ...
show more
309 attacks on password/key grabbing URLs, PHP URLs, env grabbing URLs (type 2), VC URLs, directory traversals, config grabbing URLs (type 2), env grabbing URLs:
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.aws/credentials&environmentName=rsc HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /auth.json HTTP/1.1
GET /laravel/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-16 03:28:19
(8 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-16 03:06:13
(8 hours ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฌ๐ง
pinguin
2026-09-16 02:54:07
(8 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /amplify_outputs.json
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 01:23:18
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.61.51.119 (119.51.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.51.119 (119.51.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:23:12.219987 2026] [security2:error] [pid 1775:tid 1775] [client 34.61.51.119:56740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killeenbarrelsandtotes.com"] [uri "/.htpasswd"] [unique_id "aqnvgMJvCFZftffUVf8oBgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:00:14
(10 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
kie
2026-09-16 00:22:38
(11 hours ago)
16-09-2026:00:22:12UTC [Nginx Web Server] Suspicious web request: path:/.env path:/.aws/ path:/.git ...
show more
16-09-2026:00:22:12UTC [Nginx Web Server] Suspicious web request: path:/.env path:/.aws/ path:/.git path:/.env,/.git (98 request(s)).
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:16:43
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.61.51.119 (119.51.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.51.119 (119.51.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:16:41.109353 2026] [security2:error] [pid 22556:tid 22556] [client 34.61.51.119:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kidswithcamerasmovie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kidswithcamerasmovie.com"] [uri "/z9x8c7v6b5-debug-trigger-kidswithcamerasmovie.com"] [unique_id "aqnf6ZIjTM24ZfspDK7kgwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-15 23:56:29
(11 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:11:11
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.61.51.119 (119.51.61.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.61.51.119 (119.51.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:11:03.895696 2026] [security2:error] [pid 9036:tid 9036] [client 34.61.51.119:51532] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||khovanov.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "khovanov.com"] [uri "/z9x8c7v6b5-debug-trigger-khovanov.com"] [unique_id "aqnCd7R4x7ehA7p0vVZiDAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bsoft.de
2026-09-15 21:07:10
(14 hours ago)
34.61.51.119 - - [15/Sep/2026:23:07:09 +0200] "GET /.aws/config HTTP/1.1" 499 0 "-" "Mozilla/5.0 (co ...
show more
34.61.51.119 - - [15/Sep/2026:23:07:09 +0200] "GET /.aws/config HTTP/1.1" 499 0 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-15 20:45:31
(15 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฉ๐ช
dbmwebdesign
2026-09-15 20:40:15
(15 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-15 20:04:21
(15 hours ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x)
Port Scan