๐ซ๐ฎ
as211431.net
2026-05-14 16:11:29
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /index.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
librebit
2026-03-27 09:02:43
(2 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-02-12 06:27:24
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 01:27:19.723734 2026] [security2:error] [pid 22258:tid 22258] [client 104.207.59.10:34633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artsun.com"] [uri "/api/.env"] [unique_id "aY1yx3DrhuMGtpjJFqCOsQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 01:00:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 20:00:42.833245 2026] [security2:error] [pid 23845:tid 23845] [client 104.207.59.10:14059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arnebowman.com"] [uri "/admin/.env"] [unique_id "aY0mOkpnsDL2o9-exaiFPgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 20:34:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 15:34:27.989579 2026] [security2:error] [pid 5416:tid 7421] [client 104.207.59.10:33769] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcontractingservices.com"] [uri "/wp/.git/config"] [unique_id "aYzn08EhaZCp14XQisjkzwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
OK
2026-02-10 05:44:03
(3 months ago)
HTTP/HTTPS
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 05:31:17
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 00:31:10.316978 2026] [security2:error] [pid 16295:tid 16295] [client 104.207.59.10:59787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "knoxbestos.com"] [uri "/admin/.git/config"] [unique_id "aYrCnsQdrbB08hIgb1qoHQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:21:39
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:21:31.572724 2026] [security2:error] [pid 26694:tid 26694] [client 104.207.59.10:37463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maerynray.com"] [uri "/api/.git/config"] [unique_id "aYqkO_IJD5x9o1wI6HEgZAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 23:37:14
(3 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 23:00:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:00:53.438514 2026] [security2:error] [pid 16052:tid 16052] [client 104.207.59.10:54287] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kdarmsta.com"] [uri "/app/.env"] [unique_id "aYpnJTXRNQgrnsRsVdA70AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-09 22:37:51
(3 months ago)
Blocking for trying to access an exploit file: /.aws/credentials
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 22:20:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.59.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 17:20:37.232948 2026] [security2:error] [pid 22119:tid 22119] [client 104.207.59.10:16485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hotspringstips.com"] [uri "/.env.staging"] [unique_id "aYpdtTX6BhIJ-JhPaWf-5AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-17 15:47:59
(4 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2026-01-05 20:32:27
(4 months ago)
Attempted brute force login to web vpn 18 time(s); last attempt for 2026.01.05 is noted in report ti ...
show more
Attempted brute force login to web vpn 18 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-12-21 09:27:23
(5 months ago)
Attempted brute force login to web vpn 252 time(s); last attempt for 2025.12.21 is noted in report t ...
show more
Attempted brute force login to web vpn 252 time(s); last attempt for 2025.12.21 is noted in report timestamp
show less
Hacking
Brute-Force