๐จ๐ญ
backslash
2026-10-05 04:21:00
(14 hours ago)
block ruleset honeypot detection from VN 94A4A313D6448382F283B457A9C419564BD9A72C
Bad Web Bot
๐ซ๐ท
Sklurk
2026-10-02 01:10:58
(3 days ago)
Web App Attack
Web App Attack
๐บ๐ธ
้ฌผๅฝฑ233
2026-08-26 12:34:03
(1 month ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐จ๐ฆ
1gz
2026-07-27 08:57:25
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-07-09 15:42:40
(2 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
Anonymous
2026-07-03 12:30:50
(3 months ago)
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show more
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /brands/projectiondesign/shopby/manufacturer-panasonic-rcf-supermicro-lsi-brightline-ask_proxima-projectiondesign-xyz.html | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/111.0.0.0 Safari/537.36 | (Magento Site)
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-30 02:28:06
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 117.5.152.51 (localhost): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 117.5.152.51 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 22:28:02.018647 2026] [security2:error] [pid 19719:tid 19719] [client 117.5.152.51:43664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.me.ctemdr.com"] [uri "/var/.env"] [unique_id "akMpso4BkDR6eLCvSEZBywAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 01:20:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 117.5.152.51 (localhost): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 117.5.152.51 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 21:20:46.661904 2026] [security2:error] [pid 30655:tid 30655] [client 117.5.152.51:41054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "muzenique.com"] [uri "/wp-config.php~"] [unique_id "akMZ7pdOp_KylS54gBlU1gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-06-19 11:07:34
(3 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2026-06-18 06:22:54
(3 months ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ซ๐ท
bigorre.org
2026-06-04 09:47:42
(4 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐บ๐ธ
ersei.net
2026-06-03 01:39:03
(4 months ago)
Web app exploiting
Web App Attack
๐ซ๐ท
Sklurk
2026-05-21 00:55:43
(4 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 22:26:02
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 117.5.152.51 (localhost): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 117.5.152.51 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 18:25:55.634433 2026] [security2:error] [pid 21022:tid 21022] [client 117.5.152.51:61077] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alexgitlin.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alexgitlin.com"] [uri "/npp/necromandus.htm/alexgitlin.com"] [unique_id "agJXc-V8X_Naygb2pyfJxgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-05-06 00:37:08
(4 months ago)
Web App Attack
Web App Attack