๐ฉ๐ช
EGP Abuse Dept
2026-06-21 05:44:10
(1 day ago)
Scanning for port/service exploits on tpc-027.mach3builders.nl
Port Scan
Hacking
๐ฆ๐บ
prologic
2026-06-13 18:12:03
(1 week ago)
Distributed application-layer DoS against git.mills.io (self-hosted Gitea). High-volume automated re ...
show more
Distributed application-layer DoS against git.mills.io (self-hosted Gitea). High-volume automated requests to expensive Git repository endpoints (commit/diff/blame/archive views), ~1 request per IP, spoofed browser UA, rejected with HTTP 429. Residential-proxy botnet campaign, 2026-06-13/14 UTC.
show less
DDoS Attack
Web App Attack
๐ซ๐ท
bigorre.org
2026-06-04 21:10:50
(2 weeks ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐จ๐ฆ
1gz
2026-05-19 00:37:37
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from VN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lifestyle/horoskopi-19-maj-2026-cfare-kane-rezervuar-yjet-per-ju-sot/880101/
UA: Mozilla/5.0 (X11; Linux x86_64; CentOS Ubuntu 19.04) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.5957.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-04-13 05:19:02
(2 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-10 17:10:03
(2 months ago)
(mod_security) mod_security (id:217210) triggered by 14.191.65.220 (static.vnpt.vn): 1 in the last 3 ...
show more
(mod_security) mod_security (id:217210) triggered by 14.191.65.220 (static.vnpt.vn): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 13:09:55.813099 2026] [security2:error] [pid 1779901:tid 1779901] [client 14.191.65.220:8933] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||visitcampbellford.com|F|4"] [data "GET http://visitcampbellford.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "visitcampbellford.com"] [uri "/"] [unique_id "adku4_lidbaQl6OCysx-cAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-03-06 03:26:29
(3 months ago)
invalid/bad user agent - possible botnet
...
Bad Web Bot
๐บ๐ธ
IvyBayAdmin
2026-02-14 00:55:47
(4 months ago)
[IP] - - [11/Feb/2026:01:35:46 -0800] "GET /index.php/about-ivybay-consulting/14-ivybay-consulting-q ...
show more
[IP] - - [11/Feb/2026:01:35:46 -0800] "GET /index.php/about-ivybay-consulting/14-ivybay-consulting-qualifications HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Brave Chrome/89.0.4389.72 Safari/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
IvyBayAdmin
2026-02-11 09:35:57
(4 months ago)
14.191.65.220 - - [11/Feb/2026:01:35:46 -0800] "GET /index.php/about-ivybay-consulting/14-ivybay-con ...
show more
14.191.65.220 - - [11/Feb/2026:01:35:46 -0800] "GET /index.php/about-ivybay-consulting/14-ivybay-consulting-qualifications HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Brave Chrome/89.0.4389.72 Safari/537.36"
...
show less
Email Spam
Bad Web Bot
Anonymous
2025-11-14 21:36:24
(7 months ago)
scanning http requests from known botnet
Web App Attack
๐ฎ๐ฉ
hermawan
2025-10-07 06:18:50
(8 months ago)
[Tue Oct 07 13:12:03.573307 2025] [security2:error] [pid 86789:tid 139671070734016] [client 14.191.6 ...
show more
[Tue Oct 07 13:12:03.573307 2025] [security2:error] [pid 86789:tid 139671070734016] [client 14.191.65.220:15134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "WOW64" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "228"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: WOW64 found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36 request_line = GET /index.php/profil/meteorologi/list-all-categories/4247-klimatologi/infografis/infografis-klimatologi/infografis-bulanan/infografis-bulanan-iklim-ekstrim/infografis-bulanan-iklim-ekstrim-tahun-2024/555560991-infografis-bulanan-iklim-ekstrem-curah-hujan-maksimum-bulan-mei-tahun-2024-di-provinsi-jawa-timur HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/index.php/profil/meteorologi/list-all-categorie
...
show less
Hacking
Web App Attack
๐ช๐ธ
Global Cyber Police
2025-07-27 17:02:13
(10 months ago)
Malicious bot activity detected: Hitting honeypot page (200 OK with 258/259 bytes sent).
Port Scan
Brute-Force
Web App Attack
Anonymous
2024-09-06 06:06:48
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH