🇺🇸
Penny Packer
2026-09-06 20:16:47
(41 minutes ago)
Fail2Ban apache-tripwires
Web App Attack
🇳🇱
Savvii
2026-09-06 19:53:03
(1 hour ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-09-06 18:37:46
(2 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /.env.local
UA: Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
macrob
2026-09-06 17:32:50
(3 hours ago)
2026/09/06 17:32:48 [error] 2274825#2274825: *563661461 access forbidden by rule, client: 35.231.16. ...
show more
2026/09/06 17:32:48 [error] 2274825#2274825: *563661461 access forbidden by rule, client: 35.231.16.185, server: binixo.ro, request: "GET /.git/config HTTP/2.0", host: "binixo.ro"
2026/09/06 17:32:49 [error] 2274821#2274821: *563661429 access forbidden by rule, client: 35.231.16.185, server: binixo.ro, request: "GET /.aws/config HTTP/2.0", host: "binixo.ro"
2026/09/06 17:32:49 [error] 2274821#2274821: *563661448 access forbidden by rule, client: 35.231.16.185, server: binixo.ro, request: "GET /.git/HEAD HTTP/2.0", host: "binixo.ro"
...
show less
Web App Attack
🇩🇪
big-cloud.nl
2026-09-06 14:57:50
(6 hours ago)
Try to access /@fs/src/.env?raw??
Web App Attack
🇩🇪
hidemail.app
2026-09-06 14:14:37
(6 hours ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
🇺🇸
mnsf
2026-09-06 14:05:20
(6 hours ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
🇫🇷
tecnoacquisti.com
2026-09-06 12:54:01
(8 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
🇳🇱
e.fierstra
2026-09-06 12:18:45
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-09-06 10:48:38
(10 hours ago)
35.231.16.185 - - [06/Sep/2026:12:48:37 +0200] "GET /wp-json HTTP/2.0" 404 15883 "-" "Mozilla/5.0 (W ...
show more
35.231.16.185 - - [06/Sep/2026:12:48:37 +0200] "GET /wp-json HTTP/2.0" 404 15883 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
35.231.16.185 - - [06/Sep/2026:12:48:37 +0200] "GET /z9x8c7v6b5-debug-trigger-elhacker.net HTTP/2.0" 404 15883 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
35.231.16.185 - - [06/Sep/2026:12:48:37 +0200] "GET /rclone.conf HTTP/2.0" 404 15883 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
35.231.16.185 - - [06/Sep/2026:12:48:38 +0200] "GET /.ssh/config HTTP/2.0" 404 15883 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 Edg/149.0.0.0"
...
show less
Web App Attack
Hacking
🇩🇪
maxpower
2026-09-06 10:43:05
(10 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.231.16.185 (US/United States/185.16.2 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.231.16.185 (US/United States/185.16.231.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.231.16.185 - - [06/Sep/2026:12:42:59 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 429 41 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36" "35.231.16.185" host=masterlabvideoproduzioni.it
show less
Port Scan
🇳🇱
Savvii
2026-09-06 10:38:48
(10 hours ago)
20 attempts against mh-misbehave-ban on milky
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 10:28:10
(10 hours ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/domains/gosolar.gr.l ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.gosolar.gr; logs=/var/log/httpd/domains/gosolar.gr.log; samples=/config/env/aws_credentials.env | /.ssh/id_ed25519 | /.ssh/id_rsa
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:52:14
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.231.16.185 (185.16.231.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.16.185 (185.16.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:52:08.034687 2026] [security2:error] [pid 30094:tid 30094] [client 35.231.16.185:44800] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ahuramazda.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ahuramazda.com"] [uri "/privatekey.key"] [unique_id "ap03yOksNHXXgtUxM6K90gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
tecnoacquisti.com
2026-09-06 09:50:48
(11 hours ago)
PrestaShop Security Module: dangerous stream wrapper attempt detected
Web App Attack