๐ต๐ฑ
sefinek.net
2026-09-18 16:14:03
(13 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /public_html/phpinfo.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
4server
2026-09-18 15:58:46
(13 hours ago)
[FriSep1817:58:42.7647452026][security2:error][pid3827168:tid3827292][client34.85.212.57:0]ModSecuri ...
show more
[FriSep1817:58:42.7647452026][security2:error][pid3827168:tid3827292][client34.85.212.57:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"tcservices.ch\"][uri\"/\"][unique_id\"aq1fsn6NvifRbq7qfPY5iQAAAUc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-18 14:24:14
(15 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.config/gcloud/application_default_credentials.json | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ambor
2026-09-18 14:23:52
(15 hours ago)
Honeypot triggered on tcpdata.com - Attempted to access /.git/config (git_probe). User-Agent: Mozill ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /.git/config (git_probe). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Web App Attack
๐ฎ๐น
mgarofano80
2026-09-18 13:25:36
(16 hours ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-18 11:34:44
(17 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-18 11:06:42
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:06:37.544397 2026] [security2:error] [pid 6095:tid 6095] [client 34.85.212.57:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tcid3400.atlascoombs.com"] [uri "/.git/config"] [unique_id "aq0bPUbto2LcUKovhkj_ewAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Hippoline
2026-09-18 10:21:36
(19 hours ago)
[Fri Sep 18 12:21:12.369538 2026] [authz_core:error] [pid 22934] [client 34.85.212.57:34306] AH01630 ...
show more
[Fri Sep 18 12:21:12.369538 2026] [authz_core:error] [pid 22934] [client 34.85.212.57:34306] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/cakephp
[Fri Sep 18 12:21:34.679932 2026] [authz_core:error] [pid 23885] [client 34.85.212.57:49664] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/phpinfo.php
[Fri Sep 18 12:21:34.835163 2026] [authz_core:error] [pid 23885] [client 34.85.212.57:49664] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/info.php
[Fri Sep 18 12:21:35.028550 2026] [authz_core:error] [pid 23885] [client 34.85.212.57:49664] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/php.php
[Fri Sep 18 12:21:35.192083 2026] [authz_core:error] [pid 23885] [client 34.85.212.57:49664] AH01630: client denied by server configuration: /var/www/beaufort-online.lu/web/i.php
...
show less
Brute-Force
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-09-18 06:52:58
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Petros Stefanakis
2026-09-17 03:05:48
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.85.212.57 (US/United States/57.212.8 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.85.212.57 (US/United States/57.212.85.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-17 02:41:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:41:18.578344 2026] [security2:error] [pid 7881:tid 7881] [client 34.85.212.57:35896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trinidadlimo.com"] [uri "/.git/config"] [unique_id "aqtTTnT3TboId8QVn3uK4wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-17 02:28:31
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-09-17 02:26:56
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:25:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:25:27.626813 2026] [security2:error] [pid 12678:tid 12678] [client 34.85.212.57:33990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trimandtend.com"] [uri "/.git/config"] [unique_id "aqtPl_sw8xuyPpYRZf2VqwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:29:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.85.212.57 (57.212.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:29:42.112017 2026] [security2:error] [pid 25455:tid 25455] [client 34.85.212.57:59166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "td3friendshelpingfriends.wilburmanagementgroup.com"] [uri "/.git/config"] [unique_id "aqrD9sGW5HWNM1yGhOFomwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack