๐ฎ๐ณ
evicky2002
2026-08-27 06:00:33
(11 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-08-27 05:14:36
(11 hours ago)
11 attacks on PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs:
GET /wp-config.ph ...
show more
11 attacks on PHP URLs, config grabbing URLs (type 2), VC URLs, env grabbing URLs:
GET /wp-config.php-backup HTTP/1.1
GET /config.json HTTP/1.1
GET /.git/config HTTP/1.1
GET /.env.bak HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
billfor
2026-08-26 20:00:14
(21 hours ago)
34.70.59.142 - - [26/Aug/2026:16:00:12 -0400] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Wi ...
show more
34.70.59.142 - - [26/Aug/2026:16:00:12 -0400] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 19:47:36
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.70.59.142 (142.59.70.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.70.59.142 (142.59.70.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:47:29.264091 2026] [security2:error] [pid 29614:tid 29614] [client 34.70.59.142:47876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bikinipageone.com"] [uri "/.git/config"] [unique_id "ao9C0Yjh75_jbu_UilGP4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-08-26 19:41:48
(21 hours ago)
Web App Attack
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-26 19:28:59
(21 hours ago)
cloudlinux2 fail2ban: 2026-08-26 21:24:35,342 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 21:24:35,342 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.70.59.142 - 2026-08-26 21:24:35cloudlinux2 fail2ban: 2026-08-26 21:24:46,585 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 8.228.24.203 - 2026-08-26 21:24:46cloudlinux2 fail2ban: 2026-08-26 21:24:46,565 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 8.228.24.203 - 2026-08-26 21:24:46cloudlinux2 fail2ban: 2026-08-26 21:24:46,576 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 8.228.24.203 - 2026-08-26 21:24:46cloudlinux2 fail2ban: 2026-08-26 21:24:46,695 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 8.228.24.203 - 2026-08-26 21:24:46cloudlinux2 fail2ban: 2026-08-26 21:24:46,615 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 8.228.24.203 - 2026-08-26 21:24:46cloudlinux2 fail2ban: 2026-08-26 21:24:46,605 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 8.228.24.203 - 2026-08-26 21:24:46cl
show less
Brute-Force
๐ซ๐ฎ
as211431.net
2026-08-26 19:19:32
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-08-26 19:14:22
(21 hours ago)
Scanner hitting /.git/config on ara-oman.com (GOOGL-2) โ aaguard
Brute-Force
Port Scan
๐ซ๐ท
pm33
2026-08-26 18:54:34
(22 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-08-26 18:40:58
(22 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-08-26 18:20:45
(22 hours ago)
Blocked by ConnMonitor
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-26 18:20:08
(22 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-26 18:03:09
(23 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-26 17:58:07
(23 hours ago)
34.70.59.142 - - [26/Aug/2026:11:32:03 +0200] "GET /.git/config HTTP/1.1" 403 4478 "-" "Mozilla/5.0 ...
show more
34.70.59.142 - - [26/Aug/2026:11:32:03 +0200] "GET /.git/config HTTP/1.1" 403 4478 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
34.70.59.142 - - [26/Aug/2026:18:33:44 +0200] "GET /.git/config HTTP/1.1" 403 4535 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
34.70.59.142 - - [26/Aug/2026:18:33:44 +0200] "GET /.git/config HTTP/1.1" 301 577 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
34.70.59.142 - - [26/Aug/2026:19:58:04 +0200] "GET /.git/config HTTP/1.1" 403 4527 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
34.70.59.142 - - [26/Aug/2026:18:33:44 +0200] "\x16\x03\x01" 400 489 "-" "-"
show less
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-08-26 17:57:31
(23 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-08-26 17:57 UTC
show less
Hacking
Web App Attack