๐ซ๐ท
IRISIO
2026-09-16 10:46:34
(2 days ago)
scans/SQL injection/spam posts : 840 queries
Web App Attack
SQL Injection
๐ฉ๐ช
Hazzard
2026-09-16 06:11:58
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฌ๐ง
openstrike.co.uk
2026-09-16 05:14:37
(2 days ago)
346 attacks on directory traversals, VC URLs, config grabbing URLs (type 2), env grabbing URLs, PHP ...
show more
346 attacks on directory traversals, VC URLs, config grabbing URLs (type 2), env grabbing URLs, PHP URLs, env grabbing URLs (type 2), password/key grabbing URLs:
GET /..%2f..%2f.env HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
GET /userfiles?path=../../../../.env HTTP/1.1
POST /icecoder/lib/terminal-xhr.php HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /id_ed25519 HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ท
dominioz
2026-09-16 04:44:37
(2 days ago)
2026-09-16 04:43:54 GET /.env raw - 35.237.243.98 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like ...
show more
2026-09-16 04:43:54 GET /.env raw - 35.237.243.98 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+OAI-SearchBot/1.0;++https://openai.com/searchbot) - 301 538
2026-09-16 04:43:54 GET /.env import&raw - 35.237.243.98 HTTP/2 Mozilla/5.0+(compatible;+Kimi-SearchBot/1.0;++https://kimi.ai/) - 301 556
2026-09-16 04:43:54 GET /.env.local import&raw - 35.237.243.98 HTTP/2 Mozilla/5.0+AppleWebKit/537.36+(KHTML,+like+Gecko;+compatible;+Perplexity-User/1.0;++https://perplexity.ai/perplexitybot) - 301 568
2026-09-16 04:43:54 GET /.env import&url&inline - 35.237.243.98 HTTP/2 Mozilla/5.0+(compatible;+ChatGLM-Spider/1.0;++https://zhipuai.cn/) - 301 574
2026-09-16 04:43:54 GET /.env.local raw - 35.237.243.98 HTTP/2 DuckAssistBot/1.1+(https://duckduckgo.com/duckassistbot) - 301 550
2026-09-16 04:43:54 GET /.env.production raw - 35.237.243.98 HTTP/2 Mozilla/5.0+(compatible;+MoonshotBot/1.0;++https://kimi.ai/) - 301 560
2026-09-16 04:43:54 GET /.env.development raw - 35.237.243.98 H
...
show less
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-16 04:17:15
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:24:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:24:11.529714 2026] [security2:error] [pid 17682:tid 17682] [client 35.237.243.98:58144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mycampingmall.com"] [uri "/.git/HEAD"] [unique_id "aqoL21pqSQO3ngOCf3y41gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:09:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:08:53.514385 2026] [security2:error] [pid 29496:tid 29496] [client 35.237.243.98:42064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mavikalem.org"] [uri "/.github/.env"] [unique_id "aqoIReMHzWaUyelBFpL_ewAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:09:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:08:55.349305 2026] [security2:error] [pid 26751:tid 26751] [client 35.237.243.98:47836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gabosoftware.com"] [uri "/files../.env"] [unique_id "aqn6NwG0s61gg_GdCqj19wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 01:50:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:39:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.243.98 (98.243.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:39:34.517564 2026] [security2:error] [pid 25780:tid 25780] [client 35.237.243.98:38742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daveweisman.com"] [uri "/config/.env"] [unique_id "aqnzVitQROA_kiFv3uVDagAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Trueforce Threat Report
2026-09-16 01:20:33
(2 days ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-09-16 01:17:19
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /api
UA: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
โจ
2026-09-15 23:51:11
(2 days ago)
Domain : countrylifebrewery.co.uk
Rule : config
2026-09-15 23:49:55 ***hidden-privacy*** GET /.aws/c ...
show more
Domain : countrylifebrewery.co.uk
Rule : config
2026-09-15 23:49:55 ***hidden-privacy*** GET /.aws/credentials - 443 - 35.237.243.98 HTTP/2 Mozilla/5.0 (compatible; YiBot/1.0; https://01.ai/) - countrylifebrewery.co.uk 404 0 2 1532 391 105 - -
show less
Hacking
SQL Injection
๐บ๐ธ
countdownmail.com
2026-09-15 23:44:02
(2 days ago)
Extensive web application scanning for vulnerabilities. High volume automated attack.
Bad Web Bot
Web App Attack