๐ฒ๐ฝ
octageeks.com
2026-08-12 04:06:07
(2 weeks ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ซ๐ฎ
YF
2026-08-11 17:00:44
(2 weeks ago)
Environment file probe
Web App Attack
๐ซ๐ท
Baking333
2026-08-11 16:29:10
(2 weeks ago)
[redacted] 61.206.39.5 - - [11/Aug/2026:17:29:07 +0100] "GET /.[redacted] HTTP/1.1" 302 1543 0/29485 ...
show more
[redacted] 61.206.39.5 - - [11/Aug/2026:17:29:07 +0100] "GET /.[redacted] HTTP/1.1" 302 1543 0/294854 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" [redacted] 61.206.39.5 - - [11/Aug/2026:17:29:07 +0100] "GET /.[redacted] HTTP/1.1" 302 1543 0/257175 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 14:56:33
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 61.206.39.5 (5.0/25.39.206.61.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 61.206.39.5 (5.0/25.39.206.61.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 10:56:26.242142 2026] [security2:error] [pid 4115411:tid 4115411] [client 61.206.39.5:63172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stardancertantra.com"] [uri "/.env.production"] [unique_id "ans4GlxoopWlcngsckAx0gAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-08-11 14:08:55
(2 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from JP.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from JP.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-config.php
UA: Mozilla/5.0 (Linux; Android 14) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.82 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-08-11 14:08:07
(2 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 61.206.39.5 (JP/Japan/5.0/25.39.206 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 61.206.39.5 (JP/Japan/5.0/25.39.206.61.in-addr.arpa): 1 in the last 3600 secs
show less
Web App Attack
๐จ๐ฆ
polycoda
2026-08-11 13:52:55
(2 weeks ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-08-11 13:36:08
(2 weeks ago)
Credential and secrets file probing | req: /.env.backup | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x ...
show more
Credential and secrets file probing | req: /.env.backup | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.2478.80
show less
Hacking
Web App Attack
๐ฆ๐บ
foff
2026-08-11 13:14:00
(2 weeks ago)
SQL Injection
๐ฉ๐ช
33three
2026-08-11 12:45:51
(2 weeks ago)
Fail2Ban jail WebAttack triggered
Brute-Force
Anonymous
2026-08-11 12:35:59
(2 weeks ago)
61.206.39.5 - - [11/Aug/2026:12:35:58 +0000] "GET /.env.local HTTP/1.1" 404 7849 "-" "Mozilla/5.0 (M ...
show more
61.206.39.5 - - [11/Aug/2026:12:35:58 +0000] "GET /.env.local HTTP/1.1" 404 7849 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 12:15:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 61.206.39.5 (5.0/25.39.206.61.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 61.206.39.5 (5.0/25.39.206.61.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 08:14:57.237142 2026] [security2:error] [pid 7842:tid 7842] [client 61.206.39.5:44852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lmga.net"] [uri "/.env.save"] [unique_id "ansSQV-jlT5C6kOgY6C-ewAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 11:58:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 61.206.39.5 (5.0/25.39.206.61.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 61.206.39.5 (5.0/25.39.206.61.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 07:58:29.925168 2026] [security2:error] [pid 1773529:tid 1773529] [client 61.206.39.5:44792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "listings.cruisingforsex.com"] [uri "/.env.local"] [unique_id "ansOZfTxa6jT3xYH0REZ0gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
stechusa
2026-08-11 11:41:02
(2 weeks ago)
[Askari] | country=JP | Behavior: High error rate, HTTP/1.1 only, Inhuman browsing speed, Rotating u ...
show more
[Askari] | country=JP | Behavior: High error rate, HTTP/1.1 only, Inhuman browsing speed, Rotating user agents, Rapid connection cycling
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-08-11 11:41:02
(2 weeks ago)
ELEVATED_THREAT | country=JP | ASN=IDC Frontier Inc. | 4 concurrent SYN_RECV connections (threshold= ...
show more
ELEVATED_THREAT | country=JP | ASN=IDC Frontier Inc. | 4 concurrent SYN_RECV connections (threshold=3) | HTTP/1.1 over TLS (elevated=True) | Average -7.00s between page loads (5 pages in -28.0s)
show less
Bad Web Bot
DDoS Attack