๐ฉ๐ช
FD-IX
2026-09-06 03:52:24
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-06 03:39:18
(1 week ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wordpress/ (Match: /wordpress/)
show less
Hacking
Exploited Host
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-06 00:02:40
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
consul.to
2026-09-05 22:52:37
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-05 21:59:51
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
๐ต๐ฑ
Woytass
2026-09-05 07:07:48
(1 week ago)
CSF permanent block; ports=*; (mod_security) mod_security (id:949110) triggered by 34.69.177.54 (US/ ...
show more
CSF permanent block; ports=*; (mod_security) mod_security (id:949110) triggered by 34.69.177.54 (US/United States/54.177.69.34.bc.googleusercontent.com): 5 in the last 3600 secs
show less
Web App Attack
๐ฆ๐บ
clapper
2026-09-05 06:58:28
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.69.177.54 (US/United States/54.177.69.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.69.177.54 (US/United States/54.177.69.34.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
Hazzard
2026-09-04 14:07:10
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-04 14:05:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.69.177.54 (54.177.69.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.69.177.54 (54.177.69.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:05:26.145928 2026] [security2:error] [pid 32542:tid 32542] [client 34.69.177.54:51992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.summitartists.com"] [uri "/.env"] [unique_id "aprQJpQ5cO7VbgNALH2IHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-04 13:40:10
(1 week ago)
34.69.177.54 - - [04/Sep/2026:14:40:00 +0100] "GET /.env HTTP/1.1" 403 2599 "-" "crusader-worker/1.0 ...
show more
34.69.177.54 - - [04/Sep/2026:14:40:00 +0100] "GET /.env HTTP/1.1" 403 2599 "-" "crusader-worker/1.0"
2026/09/04 14:40:00 [error] 380597#380597: *2801167 access forbidden by rule, client: 34.69.177.54, server: betatechnologies.info, request: "GET /.env HTTP/1.1", host: "freeswitch.betatechnologies.info"
2026/09/04 14:40:07 [error] 380597#380597: *2801166 access forbidden by rule, client: 34.69.177.54, server: betatechnologies.info, request: "GET //.env HTTP/1.1", host: "freeswitch.betatechnologies.info"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-04 12:31:13
(1 week ago)
Bot / seems abusive / Apache connections: 30
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 12:20:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.69.177.54 (54.177.69.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.69.177.54 (54.177.69.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:20:47.025989 2026] [security2:error] [pid 12762:tid 12762] [client 34.69.177.54:38168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "muddypuddy.com"] [uri "/wp-config.php~"] [unique_id "apq3n9irkcBoTnl2B8vdfgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
seal
2026-09-04 12:18:23
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
SSH
Brute-Force
๐ซ๐ฎ
as211431.net
2026-09-04 12:14:09
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /%2eenv
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-04 11:46:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.69.177.54 (54.177.69.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.69.177.54 (54.177.69.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:46:43.203062 2026] [security2:error] [pid 26232:tid 26232] [client 34.69.177.54:42564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.savannah-house.com"] [uri "/wp-config.php~"] [unique_id "apqvoxPWxS1OU1L78SlVFAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack