๐ซ๐ท
dynamix
2026-07-25 08:36:52
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 06:33:41
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 44.248.15.210 (ec2-44-248-15-210.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 44.248.15.210 (ec2-44-248-15-210.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 02:33:36.473217 2026] [security2:error] [pid 894239:tid 894239] [client 44.248.15.210:43914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frenosilent.com.ar.misterflores.com"] [uri "/.git/config"] [unique_id "amRYwFiYT-nCyC7v2GmNQgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-07-25 05:43:04
(8 hours ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
Anonymous
2026-07-25 04:46:05
(9 hours ago)
Trapped by Fail2Ban: Too many login failures from 44.248.15.210
Brute-Force
Hacking
Anonymous
2026-07-25 02:27:22
(11 hours ago)
2026/07/25 04:27:20 [error] 118376#118376: *59942 access forbidden by rule, client: 44.248.15.210, s ...
show more
2026/07/25 04:27:20 [error] 118376#118376: *59942 access forbidden by rule, client: 44.248.15.210, server: freeflight.org.za, request: "GET /.git/config HTTP/1.1", host: "freeflight.org.za"
2026/07/25 04:27:21 [error] 118376#118376: *59942 access forbidden by rule, client: 44.248.15.210, server: freeflight.org.za, request: "GET /.env HTTP/1.1", host: "freeflight.org.za"
2026/07/25 04:27:22 [error] 118376#118376: *59942 access forbidden by rule, client: 44.248.15.210, server: freeflight.org.za, request: "GET /.env.local HTTP/1.1", host: "freeflight.org.za"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
melroy89
2026-07-25 01:56:28
(12 hours ago)
44.248.15.210 - - [25/Jul/2026:03:54:52 +0200] "GET /assets/.env HTTP/1.1" 404 2209 "-" "Mozilla/5. ...
show more
44.248.15.210 - - [25/Jul/2026:03:54:52 +0200] "GET /assets/.env HTTP/1.1" 404 2209 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "freedomnames.org" 0.001
44.248.15.210 - - [25/Jul/2026:03:55:35 +0200] "GET /phpinfo.php HTTP/1.1" 404 2209 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "freedomnames.org" 0.000
44.248.15.210 - - [25/Jul/2026:03:55:35 +0200] "GET /info.php HTTP/1.1" 404 2209 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "freedomnames.org" 0.000
44.248.15.210 - - [25/Jul/2026:03:55:36 +0200] "GET /php.php HTTP/1.1" 404 2209 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "freedomnames.org" 0.001
44.248.15.210 - - [25/Jul/2026:03:55:36 +0200] "GET /i.php HTTP/1.1" 404 2209 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:02:23
(15 hours ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-07-24 07:26:52
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-24 06:10:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 44.248.15.210 (ec2-44-248-15-210.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 44.248.15.210 (ec2-44-248-15-210.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:10:46.140730 2026] [security2:error] [pid 3690349:tid 3690349] [client 44.248.15.210:36370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "publicmailservice.com"] [uri "/.git/config"] [unique_id "amMB5sC7o_Mhu7qgMv3hTQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 05:46:11
(1 day ago)
44.248.15.210 - - [24/Jul/2026:05:46:08 +0000] "GET /.env.local HTTP/1.1" 404 122 "-" "Mozilla/5.0 ( ...
show more
44.248.15.210 - - [24/Jul/2026:05:46:08 +0000] "GET /.env.local HTTP/1.1" 404 122 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
44.248.15.210 - - [24/Jul/2026:05:46:08 +0000] "GET /.env.production HTTP/1.1" 404 172 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 05:20:05
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 03:37:12
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ซ๐ท
mrcrassi
2026-06-07 12:53:27
(1 month ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/113.0.5669.208 Chrome/113.0.5669.208 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot