๐ฎ๐ณ
walkintoadmin
2026-09-16 14:03:26
(22 minutes ago)
.git/.env/config-credential prober; 174 reqs/2d, scanner-path ratio 0.6, 0 real-user 200s
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 12:56:00
(1 hour ago)
Searching for Explotable Web Apps (/phpinfo)
Web App Attack
Anonymous
2026-09-16 04:31:27
(9 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
JCB
2026-09-15 15:45:00
(22 hours ago)
45.138.12.13 - - [15/Sep/2026:01:57:40 +0300] "GET /.svn/wc.db HTTP/1.1" 404 236 "-" "Mozilla/5.0 (W ...
show more
45.138.12.13 - - [15/Sep/2026:01:57:40 +0300] "GET /.svn/wc.db HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36"
45.138.12.13 - - [15/Sep/2026:01:57:40 +0300] "GET /.svn/entries HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-09-15 15:05:23
(23 hours ago)
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 45 ...
show more
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 45.138.12.13 - - \[12/Sep/2026:07:24:08 +0200\] "GET /.git/HEAD HTTP/1.1" 500 409 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/116.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 13:42:00
(1 day ago)
Blocked: Reason='N/A'; Requests=
Hacking
๐ซ๐ท
geot
2026-09-15 12:26:29
(1 day ago)
GET /.svn/entries HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /.svn/wc.db HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-09-15 09:18:18
(1 day ago)
FortiWeb WAF: 192 attacks detected. Threat Score: 58650. Types: Client Management(96), Block IP List ...
show more
FortiWeb WAF: 192 attacks detected. Threat Score: 58650. Types: Client Management(96), Block IP List(96). Origin: Latvia.
show less
Web App Attack
๐ง๐ท
dominioz
2026-09-15 00:20:33
(1 day ago)
2026-09-15 00:19:36 GET /.env.bak - - 45.138.12.13 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+ ...
show more
2026-09-15 00:19:36 GET /.env.bak - - 45.138.12.13 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Safari/537.36 - 301 546
2026-09-15 00:19:36 GET /admin/.env - - 45.138.12.13 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Safari/537.36 - 301 550
2026-09-15 00:19:36 GET /admin/.env - - 45.138.12.13 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Safari/537.36 - 301 550
2026-09-15 00:19:36 GET /config.env - - 45.138.12.13 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Safari/537.36 - 301 550
2026-09-15 00:19:36 GET /config.env - - 45.138.12.13 HTTP/2 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/116.0.0.0+Safari/537.36 - 301 550
2026-09-15 00:19:36 GET /.env.production.local - - 45.138.12.13 HTTP/2 Mozilla/5.0+(Windows+
...
show less
Web App Attack
๐ฌ๐ง
Shadymint
2026-09-15 00:04:11
(1 day ago)
url probing from IP marked as abusive
Web App Attack
๐ณ๐ฑ
Eric
2026-09-14 23:43:41
(1 day ago)
[Mon Sep 14 23:43:40.671564 2026] [security2:error] [pid 2356957:tid 2356957] [client 45.138.12.13:4 ...
show more
[Mon Sep 14 23:43:40.671564 2026] [security2:error] [pid 2356957:tid 2356957] [client 45.138.12.13:45432] [client 45.138.12.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.fambus.nl"] [uri "/.git/HEAD"] [unique_id "aqiGrOANaldUIrdpcQAOoQAAAA4"]
[Mon Sep 14 23:43:40.792891 2026] [security2:error] [pid 2356957:tid 2356957] [client 45.138.12.13:45432] [client 45.138.12.13] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [
...
show less
Hacking
Web App Attack
๐ซ๐ท
UnixPrime
2026-09-14 23:30:45
(1 day ago)
45.138.12.13 - - [15/Sep/2026:01:30:43 +0200] "GET /.git/HEAD HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Wi ...
show more
45.138.12.13 - - [15/Sep/2026:01:30:43 +0200] "GET /.git/HEAD HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36"
45.138.12.13 - - [15/Sep/2026:01:30:43 +0200] "GET /.svn/wc.db HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
1gz
2026-09-14 23:03:18
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-config.php.bak
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-09-14 22:59:02
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐จ๐ฟ
Countryman
2026-09-14 22:56:01
(1 day ago)
repeated unauthorized connection attempts, host sweep, port scan
Port Scan