π§πͺ
madeit
2026-08-28 20:06:36
(15 hours ago)
Web App Attack
Anonymous
2026-08-23 13:47:25
(5 days ago)
Scanner hitting /wp-admin/install.php?step=1 on () β aaguard
Brute-Force
Port Scan
π«π·
chengkev
2026-08-23 06:36:01
(6 days ago)
Esta IP fue detectada por CrowdSec, activando crowdsecurity/jira_cve-2021-26086
Web App Attack
Hacking
π·πΊ
DZBOT
2026-07-11 04:12:34
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π―π΅
Kinsei Engineering Inc.
2026-06-29 02:02:04
(2 months ago)
UFW:High-frequency access to unused ports
Port Scan
π¬π§
OptimusGO
2026-06-18 05:42:14
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-18 06:42:14 UTC
Log evidence:
06/18/2026-06:42:13.531647 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 141.101.98.208:13744 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
π¬π§
pinguin
2026-04-14 05:37:25
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from GB.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /config.js
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
Furry Network Services
2026-04-12 00:56:47
(4 months ago)
Blocked by UFW [8080/tcp] | SPT: 11499 | TTL: 50 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sef ...
show more
Blocked by UFW [8080/tcp] | SPT: 11499 | TTL: 50 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
Furry Network Services
2026-04-11 09:54:54
(4 months ago)
Blocked by UFW [8080/tcp] | SPT: 11544 | TTL: 50 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sef ...
show more
Blocked by UFW [8080/tcp] | SPT: 11544 | TTL: 50 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
Furry Network Services
2026-04-10 01:42:00
(4 months ago)
Blocked by UFW [8080/tcp] | SPT: 12818 | TTL: 50 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sef ...
show more
Blocked by UFW [8080/tcp] | SPT: 12818 | TTL: 50 | LEN: 60 | TOS: 0x00 β’ Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-04-09 01:07:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 21:07:27.227273 2026] [security2:error] [pid 3004619:tid 3004619] [client 141.101.98.208:10338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.menafert.com"] [uri "/.env2"] [unique_id "adb7z4rCpRjdZJhdoTtrnQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 21:45:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 17:45:29.455107 2026] [security2:error] [pid 2752565:tid 2752565] [client 141.101.98.208:11722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daydar.net"] [uri "/.env.dev.local"] [unique_id "adbMeY_XQq1_jfe-NcsGcwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 20:33:19
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 16:33:11.681762 2026] [security2:error] [pid 3714305:tid 3714305] [client 141.101.98.208:13303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.catholicshopper.com"] [uri "/.env.staging"] [unique_id "ada7h5_JFpXgF6yXiX4DzAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 19:55:32
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 15:55:11.520257 2026] [security2:error] [pid 2914703:tid 2914703] [client 141.101.98.208:14180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lifevsai.com"] [uri "/app/.env"] [unique_id "adayn9pBM2hFhqYrfH3yhwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-08 19:28:48
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.98.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 15:28:42.662466 2026] [security2:error] [pid 1554269:tid 1554281] [client 141.101.98.208:11866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ecothermtech.com"] [uri "/.env.staging"] [unique_id "adasaj9iQeRd0UPUAUPXdQAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack