๐ซ๐ท
Sklurk
2026-08-01 02:23:38
(56 minutes ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-31 01:30:14
(1 day ago)
Web App Attack
Web App Attack
๐บ๐ธ
xxkodedxx
2026-05-22 21:16:27
(2 months ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 1ร edge-block in 10m window.
Origin: GB / AS200373 3xK Tech GmbH
Active: 21:16:16 UTC
Volume: 1 HTTP req
Probed: http://secondopinion.ztx-lab.com
Status mix: 444ร1
Vhost fishing: secondopinion.ztx-lab.com
UA: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-04-08 01:04:17
(3 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-24 10:17:26
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 24 05:17:19.374177 2026] [security2:error] [pid 2305:tid 2305] [client 104.207.50.99:58313] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||havelocktruckandauto.ca|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "havelocktruckandauto.ca"] [uri "/home.db"] [unique_id "aXScL4buxu7x9J_ik9W6xwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-01-02 06:03:16
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ญ
backslash
2025-12-30 21:15:02
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-12-23 02:08:27
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ต๐ฑ
sefinek.net
2025-11-25 22:59:51
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-24 05:56:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:56:06.387957 2025] [security2:error] [pid 13872:tid 13872] [client 104.207.50.99:27121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.joe.hatfulofrain.com"] [uri "/.svn/wc.db"] [unique_id "aSPzdnSYLz9IwfvVeSUvfgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Thaliruth
2025-11-24 05:53:48
(8 months ago)
104.207.50.99 - - [24/Nov/2025:06:53:48 +0100] "GET /.git/HEAD HTTP/1.1" 403 267 "-" "Mozilla/5.0 (W ...
show more
104.207.50.99 - - [24/Nov/2025:06:53:48 +0100] "GET /.git/HEAD HTTP/1.1" 403 267 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
default:80 104.207.50.99 - - [24/Nov/2025:06:53:48 +0100] "GET /.git/HEAD HTTP/1.0" 403 431 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 05:36:07
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:36:03.613240 2025] [security2:error] [pid 845:tid 845] [client 104.207.50.99:58191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.polycarbonatex.com"] [uri "/.git/HEAD"] [unique_id "aSPuww0Y4Qe5xFG2Mp7mDQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 03:04:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.50.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:04:05.120816 2025] [security2:error] [pid 24074:tid 24074] [client 104.207.50.99:45553] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.walc.net"] [uri "/.env"] [unique_id "aSPLJbxb7bRs7-t5LA3WrAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
relianoid.com
2025-11-14 05:49:13
(8 months ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
Anonymous
2025-10-16 12:01:52
(9 months ago)
[redacted] 104.207.50.99 - - [16/Oct/2025:14:01:31 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "M ...
show more
[redacted] 104.207.50.99 - - [16/Oct/2025:14:01:31 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Linux; Android 5.1.1; HUAWEI SCL-L03 Build/HuaweiSCL-L03) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Mobile Safari/537.36"
[redacted] 104.207.50.99 - - [16/Oct/2025:14:01:32 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15G77"
[redacted] 104.207.50.99 - - [16/Oct/2025:14:01:35 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-us) AppleWebKit/312.1 (KHTML, like Gecko) Safari/312"
[redacted] 104.207.50.99 - - [16/Oct/2025:14:01:38 +0200] "POST /xmlrpc.php HTTP/2.0" 200 401 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/8.0.57838 Mobile/12H321 Safari/600.1.4"
[redacted] 104.20
...
show less
Hacking
Web App Attack