๐บ๐ธ
oncord
2026-01-02 12:42:36
(5 months ago)
Form spam
Web Spam
๐ต๐ฑ
sefinek.net
2025-12-31 17:17:20
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ท
hostseries
2025-12-24 05:51:59
(5 months ago)
Trigger: LF_DISTATTACK
Brute-Force
๐ฎ๐น
VHosting
2025-12-23 11:24:09
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ต๐ฑ
sefinek.net
2025-12-22 21:25:37
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-30 13:10:03
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-24 09:20:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:20:42.188923 2025] [security2:error] [pid 29397:tid 29397] [client 104.207.32.249:21533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.torahorah.com"] [uri "/.git/HEAD"] [unique_id "aSQjahHJY-wYidOet4Ik6QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:56:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:55:57.937067 2025] [security2:error] [pid 31450:tid 31450] [client 104.207.32.249:34477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "numberseven.okwellbeing.com"] [uri "/.env"] [unique_id "aSQdnRxg0RBsUgIlyMwyigAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:28:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:28:40.097598 2025] [security2:error] [pid 32191:tid 32191] [client 104.207.32.249:24067] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.line2.biz"] [uri "/.env"] [unique_id "aSP7GIWpaNITfchaqeJNCAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:35:09
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:35:03.558084 2025] [security2:error] [pid 651:tid 651] [client 104.207.32.249:22097] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.wild-goose.net"] [uri "/.svn/wc.db"] [unique_id "aSPgd8MHq3zoAAbsXbnLJQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 15:48:21
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 10:48:16.506109 2025] [security2:error] [pid 28027:tid 28027] [client 104.207.32.249:38025] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stardancertantra.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stardancertantra.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRtDwJxz1BKuJN8mMWQBvwAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 22:06:15
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.32.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 17:06:08.289520 2025] [security2:error] [pid 10530:tid 10530] [client 104.207.32.249:45173] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||apsni.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "apsni.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aRpK0JRh-ikihwrsGDPz3QAAABs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-10-30 15:37:45
(7 months ago)
(From [email protected] ) Iโm Tracy Diacetis with Engineered Concepts Inc. Weโre curre ...
show more
(From [email protected] ) Iโm Tracy Diacetis with Engineered Concepts Inc. Weโre currently evaluating potential partners for an upcoming opportunity and would like to confirm:
Your availability for new projects in Q4 2025.
Your interest in receiving project details
Scope information will be shared upon your confirmation of availability and interest.
Looking forward to your response.
Warm regards,
Tracy
Tracy Diacetis
Office Manager
Engineered Concepts Inc.
www.engineeredconceptsinc.com
1-860-234-0109
show less
Phishing
Web Spam
Anonymous
2025-10-18 09:16:06
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-16 01:58:42
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack