๐บ๐ธ
mccsoft.io
2026-06-10 14:47:09
(1 day ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 22:07:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 18:07:11.229282 2026] [security2:error] [pid 21962:tid 21962] [client 104.23.223.142:12913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garantaconsulting.internetnameregistration.com"] [uri "/.git/config"] [unique_id "aic9D7t1OmK1cnezFJkpVgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 21:03:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:03:55.923957 2026] [security2:error] [pid 16450:tid 16450] [client 104.23.223.142:12306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "21-0322.dynamic-therapy-mn.com"] [uri "/.git/config"] [unique_id "aicuOwhk2Z7h4eFJ5gG79QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 16:02:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:02:27.407013 2026] [security2:error] [pid 2016:tid 2016] [client 104.23.223.142:13399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.maverickhousellc.com"] [uri "/.git/config"] [unique_id "aibnk5JT0IB2_7Pe9-BYvwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-05-26 21:45:23
(2 weeks ago)
Form spam
Web Spam
Anonymous
2026-05-23 16:36:03
(2 weeks ago)
104.23.223.142 - - [23/May/2026:18:36:01 +0200] "GET / HTTP/1.1" 403 5429 "-" "curl/8.4.0" ...
Web App Attack
๐ท๐บ
DZBOT
2026-05-20 02:50:25
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 10:14:07
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.223.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 06:14:01.454249 2026] [security2:error] [pid 9623:tid 9623] [client 104.23.223.142:13790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.summercampregistration.wholesalelivelobsters.com"] [uri "/.env.save"] [unique_id "agmU6c_iqPc1TIpiHrZLzQAAAAE"], referer: https://www.google.com/search?q=www.summercampregistration.wholesalelivelobsters.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-05-14 07:38:17
(4 weeks ago)
104.23.223.142 - - [14/May/2026:
...
Brute-Force
๐บ๐ธ
WellSpring
2026-05-02 21:35:11
(1 month ago)
wordpress scan on 940.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-05 09:38:08
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-193)
Hacking
๐ฌ๐ง
pinguin
2026-04-03 15:49:33
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from SE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from SE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /sid3.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-03-29 12:48:12
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-193)
Hacking
๐ซ๐ท
dynamix
2026-03-25 18:40:26
(2 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-03-22 12:57:07
(2 months ago)
104.23.223.142 - - [22/Mar/2026:14:56:27 +0200] "GET /wp-admin/setup-config.php HTTP/1.0" 404 482 "- ...
show more
104.23.223.142 - - [22/Mar/2026:14:56:27 +0200] "GET /wp-admin/setup-config.php HTTP/1.0" 404 482 "-" "https://smoongo.com/wp-admin/setup-config.php"
104.23.223.142 - - [22/Mar/2026:14:56:27 +0200] "GET /wp-admin/setup-config.php HTTP/1.1" 404 241 "-" "https://smoongo.com/wp-admin/setup-config.php"
104.23.223.142 - - [22/Mar/2026:14:56:37 +0200] "GET /wp-admin/setup-config.php HTTP/1.0" 404 482 "-" "http://smoongo.com/wp-admin/setup-config.php"
104.23.223.142 - - [22/Mar/2026:14:56:37 +0200] "GET /wp-admin/setup-config.php HTTP/1.1" 404 241 "-" "http://smoongo.com/wp-admin/setup-config.php"
104.23.223.142 - - [22/Mar/2026:14:57:06 +0200] "GET /wordpress/wp-admin/setup-config.php HTTP/1.0" 404 482 "-" "https://smoongo.com/wordpress/wp-admin/setup-config.php"
...
show less
Brute-Force
Web App Attack