Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=788; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.develo ...
show more
Apache probe; attempts=788; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.development | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.env.prod.bak | /.env.production | /.env.production.bak | /.env.staging | /.env.swp | /.env.test | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /@fs/.env?raw?? | /@fs/root/.env?raw?? | /actuator | /actuator/configprops | /actuator/env | /actuator/mappings | /admin/.env | /api/.env | /api/.env/ | /app/.env | /backend/.env | /config.env | /config/.env | /config/.env.php | /core/.env | /dev/.env | /docker/.env | /frontend/.env | /laravel/.env | /production/.env | /public/.env | /sendgrid.env | /server/.env | /src/.env | /staging/.env | /web/.env
show less
Web App Attack
🇳🇱
Site.eu
2026-07-28 08:14:15
(1 month ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
WizardsToolkit
2026-07-27 10:14:51
(1 month ago)
tried to access forbidden files; attempted to access /storage/logs/laravel.log
Web App Attack
🇳🇱
e.fierstra
2026-07-27 06:58:05
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-07-27 05:35:36
(1 month ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_client_contact
Hacking
🇩🇪
LRob
2026-07-27 03:18:27
(1 month ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/HEAD | 5 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/HEAD | 5 distinct paths | UA: Mozilla/5.0 (compatible; Bytespider; [email protected] )
show less
Hacking
🇬🇧
Marten Mark
2026-07-27 00:01:47
(1 month ago)
34.75.243.161 - - [27/Jul/2026:00:01:46 +0000] "GET /config/.env.php HTTP/2.0" 401 176 "-" "Mozilla/ ...
show more
34.75.243.161 - - [27/Jul/2026:00:01:46 +0000] "GET /config/.env.php HTTP/2.0" 401 176 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
...
show less
Web App Attack
Bad Web Bot
Anonymous
2026-07-26 22:56:42
(1 month ago)
34.75.243.161 - - [27/Jul/2026:00:56:36 +0200] "GET /rclone.conf HTTP/1.1" 403 7143 "-" "Mozilla/5.0 ...
show more
34.75.243.161 - - [27/Jul/2026:00:56:36 +0200] "GET /rclone.conf HTTP/1.1" 403 7143 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.75.243.161 - - [27/Jul/2026:00:56:36 +0200] "GET /.github/workflows/deploy.yml HTTP/1.1" 403 7143 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.75.243.161 - - [27/Jul/2026:00:56:36 +0200] "GET /.git/config HTTP/1.1" 403 7143 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.75.243.161 - - [27/Jul/2026:00:56:36 +0200] "GET /.aws/credentials HTTP/1.1" 403 7143 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user"
34.75.243.161 - - [27/Jul/2026:00:56:36 +0200] "GET /.git/HEAD HTTP/1.1" 403 7143 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHT
...
show less
DDoS Attack
🇺🇸
jormaster3k
2026-07-26 22:11:53
(1 month ago)
Attack against Apache (too many 404s)
Web App Attack
🇳🇱
Savvii
2026-07-26 20:19:45
(1 month ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-07-26 14:59:56
(1 month ago)
Accessed trap at '/.git/config'
Web App Attack
🇧🇪
voormedia
2026-07-26 13:34:26
(1 month ago)
Accessed trap at '/.aws/config'
Web App Attack
Anonymous
2026-07-26 10:32:57
(1 month ago)
Aggressive web scan
Web App Attack
🇦🇹
penguin-solutions.at
2026-07-26 10:23:38
(1 month ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇫🇷
mrcrassi
2026-07-26 10:19:20
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /ssl/localhost.key
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot