π©πͺ
marzzzello
2025-06-01 01:06:43
(1 year ago)
Ports: 5x 48097
Port Scan
π©πͺ
marzzzello
2025-06-01 01:03:23
(1 year ago)
Ports: 9x 48097
Port Scan
π¦πΊ
oncord
2025-05-06 23:28:34
(1 year ago)
Form spam
Web Spam
Anonymous
2025-03-20 16:52:08
(1 year ago)
Excessive connections to http/https ports
DDoS Attack
Anonymous
2025-03-20 16:42:08
(1 year ago)
Web Server atack
...
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-03-18 09:56:28
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
π¦πΊ
MAGIC
2025-02-28 14:07:35
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π΅π±
sefinek.net
2025-01-07 10:28:27
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 174 (COGENT- ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 174 (COGENT-174)
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
Timestamp: 2025-01-07T09:39:43Z
Ray ID: 8fe2fb72ed904276
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¦πΊ
2000cn.com.au
2025-01-07 07:17:59
(1 year ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2025-01-06 19:32:27
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 06 14:32:22.032753 2025] [security2:error] [pid 25348:tid 25467] [client 102.165.16.142:56743] [client 102.165.16.142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.castaspell.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.castaspell.com"] [uri "/site/default/settings.php.BAK"] [unique_id "Z3wvxoTNxJG425ZqT7By9wAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-01-06 12:40:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 06 07:40:13.258266 2025] [security2:error] [pid 3592342:tid 3592342] [client 102.165.16.142:56149] [client 102.165.16.142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||body-tone.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "body-tone.com"] [uri "/site/default/settings.php.BAK"] [unique_id "Z3vPLVGSWsuf9AuKghc2tgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-01-06 09:33:30
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 06 04:33:25.344189 2025] [security2:error] [pid 18645:tid 18645] [client 102.165.16.142:52243] [client 102.165.16.142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bouldercorporate.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bouldercorporate.com"] [uri "/site/default/settings.php.BAK"] [unique_id "Z3ujZa9GLbT4FDIg5Et7LgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-01-06 06:14:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 06 01:14:32.078458 2025] [security2:error] [pid 8157:tid 8157] [client 102.165.16.142:59769] [client 102.165.16.142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||morleysales.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "morleysales.com"] [uri "/site/default/settings.php.BAK"] [unique_id "Z3t0yHTYh1n7fhpDWPGqqQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-01-06 02:24:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 05 21:24:12.657327 2025] [security2:error] [pid 9086:tid 9086] [client 102.165.16.142:58128] [client 102.165.16.142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bcerg.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bcerg.org"] [uri "/site/default/settings.php.BAK"] [unique_id "Z3s-zJGGkC3P9xLSWwTbwAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-01-06 01:22:53
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 102.165.16.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 05 20:22:47.760636 2025] [security2:error] [pid 2102923:tid 2102923] [client 102.165.16.142:62196] [client 102.165.16.142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shellyfamily.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shellyfamily.com"] [uri "/site/default/settings.php.BAK"] [unique_id "Z3swZ2nJav5M0xIle3urOgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack