๐ฑ๐ป
garmtech.com
2026-07-26 03:14:45
(1 hour ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
๐ต๐ฑ
strefapi_com
2026-07-25 01:16:21
(1 day ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-07-25 00:01:32
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฌ๐ง
Oakley
2026-07-24 23:55:55
(1 day ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:00:28
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 11:17:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:17:31.659495 2026] [security2:error] [pid 549448:tid 549473] [client 35.159.98.76:43758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wbwstudio.com"] [uri "/.git/config"] [unique_id "amNJy_jjKskB4y0s_3n5QQAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-07-24 11:13:58
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-24 10:38:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:37:57.122286 2026] [security2:error] [pid 3842178:tid 3842178] [client 35.159.98.76:50540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wbcsnet.com"] [uri "/.git/config"] [unique_id "amNAhdvahnvE_7AYV78PeAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-24 08:15:01
(1 day ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 07:18:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:18:25.366054 2026] [security2:error] [pid 4081720:tid 4081720] [client 35.159.98.76:33916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "watongalodging.com"] [uri "/.git/config"] [unique_id "amMRwZ_PugUq07GgYLvnsAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-07-24 07:07:01
(1 day ago)
.git/config scan
Web App Attack
๐ฉ๐ช
XICTRON
2026-07-24 07:05:06
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:54:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.com ...
show more
(mod_security) mod_security (id:210730) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:54:06.293954 2026] [security2:error] [pid 3295948:tid 3295948] [client 35.159.98.76:44530] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||waterspell.net|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "waterspell.net"] [uri "/.env.bak"] [unique_id "amMMDrwBhIdtg1FzAITUiQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 06:28:19
(1 day ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:22:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 35.159.98.76 (ec2-35-159-98-76.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:22:38.325991 2026] [security2:error] [pid 1772668:tid 1772668] [client 35.159.98.76:42532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waterjetsolutions.com"] [uri "/.git/config"] [unique_id "amMErjQAhC42-5ZatnY3PwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack