πΊπΈ
craudiovizai
2026-09-16 06:30:36
(20 hours ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
πΊπΈ
craudiovizai
2026-09-15 00:30:40
(2 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
πΊπΈ
craudiovizai
2026-09-13 18:30:32
(3 days ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-admin/install.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
π·πΊ
DZBOT
2026-09-13 02:29:56
(4 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 01:53:32
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:53:23.933943 2026] [security2:error] [pid 11137:tid 11184] [client 104.23.217.114:10448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nederbragt.net"] [uri "/.git/config"] [unique_id "aoJpk17W0poX2GoMC3xB4AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 23:52:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:52:36.869724 2026] [security2:error] [pid 23227:tid 23240] [client 104.23.217.114:14256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.ianajewellery.com"] [uri "/.git/config"] [unique_id "aoJNRDTNFvvGrCapibQw0gAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 22:56:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:56:52.739731 2026] [security2:error] [pid 32408:tid 32408] [client 104.23.217.114:11574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.superstargambling.com"] [uri "/.git/HEAD"] [unique_id "aoJANJ1xr2Yuh6Y6HRxxmQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Blexyel
2026-08-05 16:04:19
(1 month ago)
104.23.217.114 - - [05/Aug/2026:18:04:18 +0200] "GET /wp-login.php HTTP/1.1" 403 326 "-" "-" "s3-pro ...
show more
104.23.217.114 - - [05/Aug/2026:18:04:18 +0200] "GET /wp-login.php HTTP/1.1" 403 326 "-" "-" "s3-proxied.fomx.gay"
...
show less
Brute-Force
Web App Attack
π·πΊ
DZBOT
2026-07-10 07:46:19
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π¬π§
pinguin
2026-06-30 15:33:04
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from SE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from SE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /this_is_a_new_hello_world.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π³π΄
jad-abuse
2026-06-10 22:30:58
(3 months ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Ob ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-08 22:55:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:55:24.535148 2026] [security2:error] [pid 7830:tid 7839] [client 104.23.217.114:11604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starwars.onernet.com"] [uri "/.git/config"] [unique_id "aidIXCjXFJLl-V3iDnK_8AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
strxmpp
2026-05-28 23:43:51
(3 months ago)
104.23.217.114 - - [29/May/2026:01:43:49 +0200] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 439 ...
show more
104.23.217.114 - - [29/May/2026:01:43:49 +0200] "GET /wp-admin/install.php?step=1 HTTP/2.0" 404 439 "-" "http://in-hagello.ch/wp-admin/install.php?step=1"
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-24 12:08:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 08:07:59.931386 2026] [security2:error] [pid 24392:tid 24392] [client 104.23.217.114:14014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sargentandco.com"] [uri "/sftp-config.json"] [unique_id "ahLqH1Ms3cumTwcRRcNu7QAAAAE"], referer: https://www.google.com/search?q=sargentandco.com
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-21 01:55:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.217.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 21:55:17.985978 2026] [security2:error] [pid 6367:tid 6367] [client 104.23.217.114:9521] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.otrantocapital.com"] [uri "/.env.local"] [unique_id "ag5mBfpkh1CiBzDtSa7i9gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack