Anonymous
2026-04-18 10:02:54
(1 month ago)
Forum/form spam
Web Spam
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 23:00:41
(4 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐บ๐ธ
myagent.site
2026-02-10 15:06:24
(4 months ago)
Blocking for trying to access an exploit file: /frontend/.env
Hacking
๐ฉ๐ช
big-cloud.nl
2026-02-10 04:44:52
(4 months ago)
Try to access /.aws/credentials
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:04:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:04:13.527062 2026] [security2:error] [pid 12808:tid 12828] [client 104.207.37.190:16391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madring.live"] [uri "/.env.local"] [unique_id "aYqgLStDVRwtbLhRmDQEFwAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:05:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:05:47.348630 2026] [security2:error] [pid 18178:tid 18178] [client 104.207.37.190:29277] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentuckianacordcutters.com"] [uri "/app/.git/config"] [unique_id "aYp2W7FesTyNpi85hYmIRwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 22:15:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:15:27.237763 2026] [security2:error] [pid 22752:tid 22752] [client 104.207.37.190:9259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotline-srm.com"] [uri "/api/.env"] [unique_id "aYpcf9s6-54n6XMhIF4MkQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:09:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:09:35.816700 2026] [security2:error] [pid 16011:tid 16011] [client 104.207.37.190:36437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "karenjoyce.com"] [uri "/site/.git/config"] [unique_id "aYpNDzu5sqva2S0yTY2h7wAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:19:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.37.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:18:54.865754 2026] [security2:error] [pid 11174:tid 11174] [client 104.207.37.190:23927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kampinenlaw.com"] [uri "/app/.env"] [unique_id "aYpBLnHg8yHo5mQqBblntgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-26 07:26:04
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ต๐ฑ
sefinek.net
2025-12-12 02:11:23
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
RLDD
2025-11-23 11:28:45
(6 months ago)
WP probing -nov
Web App Attack
๐ฆ๐บ
oncord
2025-11-21 02:56:09
(6 months ago)
Form spam
Web Spam
Anonymous
2025-11-16 07:11:59
(6 months ago)
Attempted brute force login to web vpn 36 time(s); last attempt for 2025.11.16 is noted in report ti ...
show more
Attempted brute force login to web vpn 36 time(s); last attempt for 2025.11.16 is noted in report timestamp
show less
Hacking
Brute-Force