๐บ๐ธ
TPI-Abuse
2026-06-06 11:39:29
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 101.47.26.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 101.47.26.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 07:39:25.896284 2026] [security2:error] [pid 10582:tid 10582] [client 101.47.26.35:13095] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fiasdesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fiasdesigns.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aiQG7Vniz2FVWgTv5oxR_wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-06-05 15:08:23
(2 days ago)
Web App Attack
Web App Attack
๐จ๐ฆ
1gz
2026-06-04 06:03:11
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /kuriozitete/vendi-i-gjyshrve-projekti-ideal-pr-t-jetuar-n-botn-virtuale-pa-/265299/
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ersei.net
2026-06-02 08:00:08
(5 days ago)
Web app exploiting
Web App Attack
๐ซ๐ท
Sklurk
2026-06-01 01:34:05
(1 week ago)
Web App Attack
Web App Attack
๐บ๐ธ
stechusa
2026-05-27 18:31:20
(1 week ago)
[Askari] | Behavior: Holding server worker, Targeting specific pages, Outdated browser, Concurrent p ...
show more
[Askari] | Behavior: Holding server worker, Targeting specific pages, Outdated browser, Concurrent page load during attack, HTTP/1.1 over TLS
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-05-27 18:31:19
(1 week ago)
ELEVATED_THREAT | 49 IPs targeting /brand/satco-products-inc.html | Facet request during elevated th ...
show more
ELEVATED_THREAT | 49 IPs targeting /brand/satco-products-inc.html | Facet request during elevated threat (facet_ratio=0.70, unique_ips=345) | HTTP/1.1 over TLS (elevated=True)
show less
Bad Web Bot
DDoS Attack
๐ซ๐ท
Sklurk
2026-05-27 06:15:23
(1 week ago)
Web App Attack
Web App Attack
๐บ๐ธ
stechusa
2026-05-26 20:01:42
(1 week ago)
[Askari] | country=SG | ASN=Byteplus Pte. Ltd. | Behavior: HTTP/1.1 over TLS, Outdated browser
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-05-26 20:01:42
(1 week ago)
country=SG | ASN=Byteplus Pte. Ltd. | AbuseIPDB=44% | form_key Ta7n0J9M... shared by 2 IPs: 101.47.2 ...
show more
country=SG | ASN=Byteplus Pte. Ltd. | AbuseIPDB=44% | form_key Ta7n0J9M... shared by 2 IPs: 101.47.26.35, 101.47.24.67 | HTTP/1.1 over TLS (elevated=True) | 403 on protected endpoint: /catalog/product_compare/add/product/39468/uenc/aHR0cHM6Ly93d3cubGlnaHRpbmcybGln (method=GET, ModSec blocked)
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-05-26 01:43:17
(1 week ago)
[Askari] | country=SG | Behavior: HTTP/1.1 over TLS, Outdated browser
Bad Web Bot
DDoS Attack
๐บ๐ธ
stechusa
2026-05-26 01:43:17
(1 week ago)
ELEVATED_THREAT | country=SG | ASN=Byteplus Pte. Ltd. | AbuseIPDB=44% | form_key tcu5azMw... shared ...
show more
ELEVATED_THREAT | country=SG | ASN=Byteplus Pte. Ltd. | AbuseIPDB=44% | form_key tcu5azMw... shared by 2 IPs: 45.184.221.234, 101.47.26.35 | HTTP/1.1 over TLS (elevated=True) | GET to POST-only endpoint: /wishlist/index/add/product/40010/form_key/tcu5azMwO1Z1tlQ0/ (status=403)
show less
Bad Web Bot
DDoS Attack
๐จ๐ฆ
polycoda
2026-05-24 13:21:44
(2 weeks ago)
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
๐จ๐ฆ
1gz
2026-05-21 03:24:41
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /shqiperi/-cako-takim-me-drejtuesin-e-policise-dhe-shefin-e-inteligjences-ne-new/247568/kerko.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
Sklurk
2026-05-20 10:47:16
(2 weeks ago)
Web App Attack
Web App Attack