Anonymous
2026-06-08 01:38:07
(17 minutes ago)
Try to connect to Port_Scan_443_stealth
Port Scan
๐ซ๐ท
pm33
2026-06-08 01:31:55
(23 minutes ago)
Unauthorized connections HTTP 403
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-08 01:14:44
(40 minutes ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐ต๐ฑ
strefapi_com
2026-06-08 01:13:47
(41 minutes ago)
Brute-force on web app
...
Brute-Force
Web App Attack
๐ฌ๐ง
andypiper
2026-06-08 01:02:48
(52 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
tall1oN
2026-06-08 01:01:51
(53 minutes ago)
86.104.192.255 - - [08/Jun/2026:03:01:23 +0200] "GET /backup.sql HTTP/2.0" 200 5745 "-" "Mozilla/5.0 ...
show more
86.104.192.255 - - [08/Jun/2026:03:01:23 +0200] "GET /backup.sql HTTP/2.0" 200 5745 "-" "Mozilla/5.0 (compatible; WhiteWebSecurity/1.0; +https://whitewebsecurity.com; [email protected] )" "exatek.de"
86.104.192.255 - - [08/Jun/2026:03:01:51 +0200] "GET /.env.staging HTTP/2.0" 200 5745 "-" "Mozilla/5.0 (compatible; WhiteWebSecurity/1.0; +https://whitewebsecurity.com; [email protected] )" "exatek.de"
...
show less
Web App Attack
Port Scan
Hacking
๐ฌ๐ง
Smish
2026-06-08 00:10:25
(1 hour ago)
HONEYPOT HIT --> Fail2ban time=1780877424 log=2026-06-08T01:10:24+01:00 ip=86.104.192.255 host=eu.sm ...
show more
HONEYPOT HIT --> Fail2ban time=1780877424 log=2026-06-08T01:10:24+01:00 ip=86.104.192.255 host=eu.smishcraft.com method=HEAD uri="/.env.staging.swp" status=404 ua="Mozilla/5.0 (compatible; WhiteWebSecurity/1.0; +https://whitewebsecurity.com; [email protected] )" ref="-" rid=0944fe0981bfcb9881e81e76f9b59907
show less
Web App Attack
๐ฆ๐บ
FEWA
2026-06-08 00:00:10
(1 hour ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-06-07 23:45:12
(2 hours ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (HE ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /.circleci/config.yml
UA: Mozilla/5.0 (compatible; WhiteWebSecurity/1.0; +https://whitewebsecurity.com; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Rip
2026-06-07 23:37:49
(2 hours ago)
Automated recon attempt targeting restricted and sensitive paths.
Web App Attack
๐ฌ๐ง
Apache
2026-06-07 23:16:22
(2 hours ago)
(mod_security) mod_security (id:920440) triggered by 86.104.192.255 (RO/Romania/-): 5 in the last 30 ...
show more
(mod_security) mod_security (id:920440) triggered by 86.104.192.255 (RO/Romania/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-07 21:59:21
(3 hours ago)
Auto-ban: >3000 req/min op 2026-06-07
Web App Attack
SSH
Hacking
๐ซ๐ท
ELYAZ
2026-06-07 21:36:17
(4 hours ago)
(y3) Failed access -byebye- from 86.104.192.255 (RO/Romania/-): (CF_ENABLE)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-07 21:27:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 86.104.192.255 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 86.104.192.255 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 17:27:36.422905 2026] [security2:error] [pid 11619:tid 11619] [client 86.104.192.255:33303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web243.dnchosting.com"] [uri "/.env.production.swp"] [unique_id "aiXiSCduXN5KVYat8HgsSgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 21:12:14
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 86.104.192.255 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 86.104.192.255 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 17:12:07.690557 2026] [security2:error] [pid 22205:tid 22205] [client 86.104.192.255:43384] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robertmcatee.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robertmcatee.com"] [uri "/dump.sql"] [unique_id "aiXep1Ak0CfzciZ97X1UBAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack