Anonymous
2026-09-01 11:11:07
(3 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 11:07:45
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (115.99.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (115.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:07:37.889241 2026] [security2:error] [pid 32528:tid 32528] [client 34.74.99.115:60166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.automationworkflow.com"] [uri "/wp-config.php.swp"] [unique_id "apax-YjFOY2_Gd49WKzPtQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:35:01
(4 hours ago)
suspicious request in access.log
Web App Attack
๐ง๐ช
FrankNeirynck
2026-09-01 10:16:03
(4 hours ago)
[2026-09-01 12:16:03 +0200] [1483] [WARNING] โ ๏ธ ๐ 34.74.99.115 "GET /wp-config.php.swp HTTP/1.1" 404 ...
show more
[2026-09-01 12:16:03 +0200] [1483] [WARNING] โ ๏ธ ๐ 34.74.99.115 "GET /wp-config.php.swp HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
[2026-09-01 12:16:03 +0200] [1483] [WARNING] โ ๏ธ ๐ 34.74.99.115 "GET /wp-config.php.bak HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
[2026-09-01 12:16:03 +0200] [1483] [WARNING] โ ๏ธ ๐ 34.74.99.115 "GET /wp-config.php~ HTTP/1.1" 404 1317 "-" "crusader-worker/1.0"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 10:15:55
(4 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-09-01 09:37:29
(4 hours ago)
[TueSep0111:37:24.3583722026][security2:error][pid3982568:tid3982625][client34.74.99.115:0]ModSecuri ...
show more
[TueSep0111:37:24.3583722026][security2:error][pid3982568:tid3982625][client34.74.99.115:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"spicydesign.ch.136-243-54-122.cpanel.site\"][uri\"/storage/logs/laravel.log\"][unique_id\"apac1PMQLWuOM0u8zsoAOQAAAFI\"]
show less
Port Scan
Brute-Force
Web App Attack
๐จ๐ฆ
polycoda
2026-09-01 08:53:57
(5 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
enjoyably
2026-09-01 08:52:35
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Hazzard
2026-09-01 08:49:19
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 07:38:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (115.99.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (115.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:38:37.902034 2026] [security2:error] [pid 31062:tid 31062] [client 34.74.99.115:49892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yuanwei.l3l4.com"] [uri "/.env.local"] [unique_id "apaA_bgQeJ8Jxh9nq-5JowAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-01 07:32:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (US/United States/115.99.74.34.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (US/United States/115.99.74.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2026-09-01 07:13:51
(7 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php.bak
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-01 06:30:50
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:13:30
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (115.99.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.99.115 (115.99.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:13:22.970713 2026] [security2:error] [pid 15377:tid 15377] [client 34.74.99.115:44480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.abraxasstudio.com"] [uri "/.env"] [unique_id "apZtApa1527tKUuT9ZhR-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 04:42:10
(9 hours ago)
Multiple WAF Violations
Web App Attack