๐ง๐ท
chronos
2026-07-30 21:55:11
(1 month ago)
Generic malicious activity: Tentativa de varredura de porta TCP... | Port: 59601 | Proto: TCP | Loca ...
show more
Generic malicious activity: Tentativa de varredura de porta TCP... | Port: 59601 | Proto: TCP | Location: Brazil, Sรฃo Paulo
show less
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-22 07:46:59
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 149.102.233.186 (unn-149-102-233-186.datapacket ...
show more
(mod_security) mod_security (id:225170) triggered by 149.102.233.186 (unn-149-102-233-186.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 03:46:55.816837 2026] [security2:error] [pid 9358:tid 9358] [client 149.102.233.186:64598] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.daisydoesoap.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.daisydoesoap.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ahAJ7xVTRYyoMfSeKopBggAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 17:42:52
(4 months ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyt
2026-04-26 12:05:39
(4 months ago)
Scanner UA
Bad Web Bot
Web App Attack
๐ซ๐ท
pocketpark
2026-04-26 11:19:50
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /wp-content/plugins/ninja-forms/assets/js/min/front-end.js | UA: Mozilla/5.0 (compatible; SecurityScanner/1.0) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
conseilgouz
2026-04-26 09:45:55
(4 months ago)
vee-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms/assets/js/min/front-en ...
show more
vee-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms/assets/js/min/front-end.js
show less
Hacking
๐ฉ๐ช
Didier Lagaert
2026-04-26 09:10:53
(4 months ago)
lie-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms-uploads/assets/js/nfpl ...
show more
lie-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms-uploads/assets/js/nfpluginsettings.js
show less
Hacking
๐ฉ๐ช
conseilgouz
2026-04-26 07:33:07
(4 months ago)
lae-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms-uploads/assets/js/nfpl ...
show more
lae-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms-uploads/assets/js/nfpluginsettings.js
show less
Hacking
๐ฉ๐ช
conseilgouz
2026-04-26 07:13:38
(4 months ago)
ave-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms/assets/js/min/front-en ...
show more
ave-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms/assets/js/min/front-end.js
show less
Hacking
๐ท๐บ
DZBOT
2026-04-26 07:07:47
(4 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ฎ
as211431.net
2026-04-26 05:31:32
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from BR.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-content/plugins/ninja-forms/assets/js/min/front-end.js
UA: Mozilla/5.0 (compatible; SecurityScanner/1.0)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
conseilgouz
2026-04-26 05:09:55
(4 months ago)
doe-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms/assets/js/min/front-en ...
show more
doe-7 : Trying access unauthorized files/dir=>/wp-content/plugins/ninja-forms/assets/js/min/front-end.js
show less
Hacking
๐ง๐ช
cmbplf
2026-04-16 13:26:22
(5 months ago)
3.363 requests with url.path */xmlrpc.php
553 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-16 13:12:42
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 149.102.233.186 (unn-149-102-233-186.datapacket ...
show more
(mod_security) mod_security (id:225170) triggered by 149.102.233.186 (unn-149-102-233-186.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 09:12:35.117490 2026] [security2:error] [pid 1379552:tid 1379552] [client 149.102.233.186:52909] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.farsipraiseclub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.farsipraiseclub.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aeDgQ7VncdnDNMJP1QT_3QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2026-04-16 11:49:08
(5 months ago)
BadRequest
Web App Attack