๐บ๐ธ
TPI-Abuse
2026-08-28 10:59:26
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.196.95.221 (221.95.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.95.221 (221.95.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:59:17.773557 2026] [security2:error] [pid 9737:tid 9737] [client 35.196.95.221:47664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.naturallyneworleans.anthonyjoseph.us"] [uri "/wp-config.php~"] [unique_id "apFqBUBdTFRx_bxRhlnH6wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
miszterx.hu
2026-08-28 06:59:22
(4 hours ago)
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 19x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ซ๐ท
service Informatique
2026-08-28 04:00:37
(7 hours ago)
GET /wp-config
Web App Attack
๐บ๐ธ
infra-monitor
2026-08-27 23:00:05
(12 hours ago)
Automated ban via infra-monitor: suspicious-probe, wordpress-probe, wp-sensitive-paths, +3 more
Port Scan
Web App Attack
๐ช๐ธ
alferez
2026-08-27 22:02:56
(13 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 21:59:48
(13 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฉ๐ช
gadix
2026-08-27 21:54:20
(13 hours ago)
[27/Aug/2026:23:54:19.587746 +0200] apCyCz0uOXIrZQMvSXAYEAAAAA0 35.196.95.221 38138 127.0.0.1 7081
[ ...
show more
[27/Aug/2026:23:54:19.587746 +0200] apCyCz0uOXIrZQMvSXAYEAAAAA0 35.196.95.221 38138 127.0.0.1 7081
[27/Aug/2026:23:54:19.629552 +0200] apCyCz0uOXIrZQMvSXAYEQAAAAU 35.196.95.221 38156 127.0.0.1 7081
[27/Aug/2026:23:54:19.634178 +0200] apCyCz0uOXIrZQMvSXAYEwAAAA4 35.196.95.221 38208 127.0.0.1 7081
...
show less
Web App Attack
๐ฎ๐น
Inartis
2026-08-27 20:26:09
(15 hours ago)
35.196.95.221 - - [27/Aug/2026:22:26:09 +0200] "GET /.env HTTP/1.1" 404 5152 "-" "crusader-worker/1. ...
show more
35.196.95.221 - - [27/Aug/2026:22:26:09 +0200] "GET /.env HTTP/1.1" 404 5152 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-27 20:03:35
(15 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //.env
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ช
boxed-it
2026-08-27 19:34:31
(16 hours ago)
GET /_ignition/health-check (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
๐จ๐ญ
zynex
2026-08-27 19:11:04
(16 hours ago)
URL Probing: /wp-config.php~
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:26:49
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.95.221 (221.95.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.95.221 (221.95.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:26:41.129926 2026] [security2:error] [pid 24529:tid 24529] [client 35.196.95.221:35770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pilgrimpastor.my1611.com"] [uri "/wp-config.php.swp"] [unique_id "apCBYVJBfM9KPHygOpQyHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-08-27 18:22:17
(17 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /.env.local | 2026-08-27 18:22 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 18:06:45
(17 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.production (+12 more) | 2026-08-27 18:06 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-27 18:06:07
(17 hours ago)
Trying to access config files
Web App Attack