๐ง๐ช
cmbplf
2026-10-10 04:33:03
(1 day ago)
134 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-10 01:37:02
(1 day ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-10-09 22:35:34
(1 day ago)
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subreq ...
show more
ModSecurity OWASP CRS (Anomaly Score: 45): HTTP header is restricted by policy (/x-middleware-subrequest/);JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;OS File Access Attempt;Remote Command Execution: Unix Shell Code Found;
show less
Web App Attack
๐ฌ๐ง
Apache
2026-10-09 22:33:47
(1 day ago)
(mod_security) mod_security (id:930120) triggered by 35.186.169.118 (US/United States/118.169.186.35 ...
show more
(mod_security) mod_security (id:930120) triggered by 35.186.169.118 (US/United States/118.169.186.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-10-09 18:29:04
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /api%2F.env
UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 13:12:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.186.169.118 (118.169.186.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.186.169.118 (118.169.186.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 09:12:25.416806 2026] [security2:error] [pid 16999:tid 16999] [client 35.186.169.118:59194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.yourmac.co.uk"] [uri "/.htpasswd"] [unique_id "asjoOV2pDzzF1xpPORKZdQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sigurg
2026-10-09 09:51:36
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐ซ๐ท
dragonv
2026-10-09 09:39:56
(2 days ago)
fail2ban nginx-botsearch: brute-force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-10-09 07:22:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.186.169.118 (US/United States/118.169.186.35 ...
show more
(mod_security) mod_security (id:210492) triggered by 35.186.169.118 (US/United States/118.169.186.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2026-10-09 05:56:45
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /cgi-bin/php-cgi.exe
UA: CCBot/2.0 (https://commoncrawl.org/faq/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
CrownSync.uk
2026-10-09 05:54:21
(2 days ago)
Automated detection: repeated HTTP 4xx scan-burst against a public web endpoint.
Port Scan
Web App Attack
Anonymous
2026-10-09 05:34:00
(2 days ago)
SQL Injection Attack, SQL authentication bypass attempts, Remote Command Execution: Unix Shell Code ...
show more
SQL Injection Attack, SQL authentication bypass attempts, Remote Command Execution: Unix Shell Code Found, etc.
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-09 05:14:41
(2 days ago)
1785 attacks on env grabbing URLs, shell probes, VC URLs, config grabbing URLs (type 2), directory t ...
show more
1785 attacks on env grabbing URLs, shell probes, VC URLs, config grabbing URLs (type 2), directory traversals, PHP URLs, password/key grabbing URLs, env grabbing URLs (type 2):
GET /_image?href=/../../../.env HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /settings.json HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
POST /index.php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-09 05:08:02
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02]
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-09 04:07:02
(2 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack