π¨π¦
1gz
2026-03-09 09:14:42
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/lifestyle/
UA: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3285.174 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
ph
2026-03-07 10:23:06
(2 months ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
π¨π¦
1gz
2026-03-04 16:58:26
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /showbiz/mberrin-nje-zarf-ne-shtepine-e-bbv-ja-cfare-ndodhi/862687/
UA: Mozilla/5.0 (Windows 7 Enterprise; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.6099.71 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π§π·
leolemos
2026-03-03 21:34:22
(3 months ago)
104.28.160.166 - - [03/Mar/2026:18:34:19 -0300] "POST /xmlrpc.php HTTP/2.0" 301 517 "-" "Mozilla/5.0 ...
show more
104.28.160.166 - - [03/Mar/2026:18:34:19 -0300] "POST /xmlrpc.php HTTP/2.0" 301 517 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.28.160.166 - - [03/Mar/2026:18:34:20 -0300] "POST /xmlrpc.php HTTP/2.0" 301 348 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.28.160.166 - - [03/Mar/2026:18:34:21 -0300] "POST /xmlrpc.php HTTP/2.0" 301 348 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
104.28.160.166 - - [03/Mar/2026:18:34:22 -0300] "POST /xmlrpc.php HTTP/2.0" 301 348 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-02 10:04:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.28.160.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.160.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 05:04:23.402419 2026] [security2:error] [pid 3736:tid 3736] [client 104.28.160.166:62001] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centreguephel.org"] [uri "/sftp-config.json"] [unique_id "aaVgp_plJpqforIVMHgliAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-02 09:43:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.28.160.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.160.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 04:43:41.855596 2026] [security2:error] [pid 29410:tid 29410] [client 104.28.160.166:62724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doorofhopechurch.org"] [uri "/sftp-config.json"] [unique_id "aaVbzTTFHD7J_isRSrdbDgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-03-02 01:13:11
(3 months ago)
Try to access /xmlrpc.php
Web App Attack
πΊπΈ
www.winos.me
2026-02-28 11:28:16
(3 months ago)
Banned due to high error rate on HTTP/1.1 protocol
Brute-Force
Web App Attack
π¨π¦
1gz
2026-02-28 06:34:00
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π³π±
EGP Abuse Dept
2026-02-28 03:58:28
(3 months ago)
Scanning for web/db/file exploits on www.brederaad-010.nl
SQL Injection
Bad Web Bot
Web App Attack
π©πͺ
LRob.fr
2026-02-19 21:45:02
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-02-15 19:42:41
(3 months ago)
Try to access /xmlrpc.php
Web App Attack
π¬π§
consul.to
2026-02-13 00:40:10
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
Hary74656
2026-01-29 11:13:10
(4 months ago)
[Thu Jan 29 12:12:59.229293 2026] [authz_core:error] [pid 119016:tid 119138] [client 104.28.160.166: ...
show more
[Thu Jan 29 12:12:59.229293 2026] [authz_core:error] [pid 119016:tid 119138] [client 104.28.160.166:15044] AH01630: client denied by server configuration: /home/harald/www/aschi.at/xmlrpc.php
...
show less
Bad Web Bot
π«π·
dynamix
2026-01-29 06:39:53
(4 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack