๐ฉ๐ช
nyuuzyou
2026-09-11 22:33:17
(2 weeks ago)
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on applic ...
show more
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on application ports 80/443. Observed 2026-09-11T22:33:17Z.
show less
Bad Web Bot
๐จ๐ฆ
1gz
2026-07-26 07:45:18
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (GET m ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/regjistrohet
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-10 11:55:13
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-06 02:05:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 22:05:54.318209 2026] [security2:error] [pid 30359:tid 30359] [client 103.142.140.151:11140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.bak" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hazardvillefire.org"] [uri "/wp-config.bak"] [unique_id "aksNgrmfkkdJAlZnCdUb2gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 19:27:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 15:27:38.910894 2026] [security2:error] [pid 27641:tid 27641] [client 103.142.140.151:57024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalvillagecambodia.org"] [uri "/.env.local"] [unique_id "akqwKsC7tuEa614rLu4LJwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 21:12:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 17:12:20.891654 2026] [security2:error] [pid 29202:tid 29202] [client 103.142.140.151:56534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "busengakko.org"] [uri "/.env.local"] [unique_id "akWCtG35w5N34ZR9Ul6ASgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 18:36:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 14:36:25.385997 2026] [security2:error] [pid 26778:tid 26778] [client 103.142.140.151:23072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "britishfolk.org"] [uri "/.env.example"] [unique_id "akVeKQPRYICHjIR7ZWvDqwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 22:17:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 18:17:12.329882 2026] [security2:error] [pid 11982:tid 11982] [client 103.142.140.151:35532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avalonestates.org"] [uri "/.env.example"] [unique_id "akRAaLMe4UtNpaqmjtNUEAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 21:35:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 103.142.140.151 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 17:35:06.818843 2026] [security2:error] [pid 27788:tid 27800] [client 103.142.140.151:31214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accreditedfinancialanalyst.org"] [uri "/.git/config"] [unique_id "akLlCl4bj8ZSnsAiuD7zeAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-03-02 23:16:10
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 Edg/128.0.0.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐น
VHosting
2026-02-24 10:34:16
(7 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐ฎ๐ณ
liveaspankaj
2026-02-20 23:22:06
(7 months ago)
DDoS attack: 146 requests in 5m (GET / or repair.php).
DDoS Attack
๐ช๐ธ
el-brujo
2025-12-23 05:10:00
(9 months ago)
DDoS Attack Layer 7
DDoS Attack
๐จ๐ญ
Zeprax
2025-12-18 13:36:50
(9 months ago)
Layer 7 Flood Detected
DDoS Attack
๐ช๐ธ
el-brujo
2025-12-17 15:47:07
(9 months ago)
Cloudflare WAF: Request Path: /ptbttest Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (W ...
show more
Cloudflare WAF: Request Path: /ptbttest Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: KIRINONET Country: SG Method: GET Timestamp: 2025-12-17T15:47:07Z ruleId: 12b9aecf1f6245b29d7e842bf35a42a0. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack