π«π·
ELYAZ
2026-06-10 12:52:05
(2 weeks ago)
(y4) Failed scan -byebye- from 104.207.39.249 (US/United States/-): (CF_ENABLE)
Hacking
Anonymous
2026-06-10 08:22:34
(2 weeks ago)
Web attack blocked by Wordfence on heemkundesjin.nl (1 hit). Reported by CRMON.
Web App Attack
π¦πΊ
MAGIC
2026-06-10 02:04:46
(2 weeks ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π©πͺ
iNetWorker
2026-06-06 10:47:04
(2 weeks ago)
trolling for resource vulnerabilities
Web App Attack
πͺπΈ
librebit
2026-06-06 07:48:53
(2 weeks ago)
Brute force
Brute-Force
πΊπΈ
ctrlpew
2026-05-19 00:51:08
(1 month ago)
WordPress login brute-force botnet targeting ctrlpew.com. Distributed attack cycling IPs every 3 sec ...
show more
WordPress login brute-force botnet targeting ctrlpew.com. Distributed attack cycling IPs every 3 seconds with UA rotation (Chrome/Safari). Target usernames do not exist. 2026-05-18.
show less
Brute-Force
Web App Attack
π¦πΊ
RedBear IT
2026-03-26 10:00:37
(3 months ago)
"DDoS against public endpoint"
DDoS Attack
π΅π±
sefinek.net
2026-01-14 01:55:12
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-11-25 06:01:32
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:01:21.591649 2025] [security2:error] [pid 13755:tid 13799] [client 104.207.39.249:55763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.progenicyte.org"] [uri "/.svn/wc.db"] [unique_id "aSVGMfPKifHcHLquJ66KSwAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 05:26:41
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:26:37.032858 2025] [security2:error] [pid 20415:tid 20415] [client 104.207.39.249:37125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jhreid.com"] [uri "/.env"] [unique_id "aSU-Dcug-_oIRKLxx6IMOAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 05:05:45
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:05:35.743963 2025] [security2:error] [pid 4993:tid 4993] [client 104.207.39.249:41443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.grollman.com"] [uri "/.env"] [unique_id "aSU5HyoFAErsG0wthCsRkwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 04:19:30
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:19:25.959297 2025] [security2:error] [pid 21930:tid 21930] [client 104.207.39.249:27711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gdhlgroup.com"] [uri "/.git/HEAD"] [unique_id "aSUuTbNCB2wwvnMglWAijAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 03:37:40
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:37:35.270038 2025] [security2:error] [pid 22153:tid 22153] [client 104.207.39.249:13273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ebookplanner.xyz"] [uri "/.env"] [unique_id "aSUkfwfuAOhMH5vjWo-HMwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-25 03:09:04
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.39.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:09:01.690992 2025] [security2:error] [pid 21211:tid 21211] [client 104.207.39.249:47953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kompassconsulting.com"] [uri "/.svn/wc.db"] [unique_id "aSUdzQVfd0z7PlzJho6nfAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2025-11-25 01:15:35
(7 months ago)
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/.svn/wc.db) detected. Automated scan or unauthorized probing.
show less
Web App Attack