๐บ๐ธ
Charlesiv
2025-08-29 09:10:54
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
ASN: 16509 (AMAZON-02)
Protoc ...
show more
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
ASN: 16509 (AMAZON-02)
Protocol: HTTP/1.1 (GET method)
Endpoint: /sftp.json
Timestamp: 2025-08-29T08:03:42Z
Ray ID: 976a888c0df13b27
UA: http://Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.134 Safari/537.36
show less
Bad Web Bot
๐ซ๐ฎ
as211431.net
2025-08-29 08:25:36
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /sftp-config.json
UA: http://Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/5.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.3; .NET4.0C; .NET4.0E)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
technojoe99
2025-08-29 07:45:34
(1 year ago)
Exploit scan from 15.207.110.229. GET /sftp.json HTTP/1.1.
Web App Attack
๐ซ๐ท
IRISIO
2025-08-29 07:39:26
(1 year ago)
scans/SQL injection/spam posts : 410 queries
SQL Injection
Web App Attack
๐บ๐ธ
vestibtech
2025-08-29 07:34:45
(1 year ago)
15.207.110.229 - - [29/Aug/2025:01:34:44 -0600] "GET /sftp-config.json HTTP/1.1" 301 462 "-" "http:/ ...
show more
15.207.110.229 - - [29/Aug/2025:01:34:44 -0600] "GET /sftp-config.json HTTP/1.1" 301 462 "-" "http://Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; EIE10;ENUSMSE; rv:11.0) like Gecko"
...
show less
Web App Attack
๐บ๐ธ
MogBox
2025-08-29 07:00:45
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 15.207.110.229 (IN/India/ec2-15-207-110-229.ap- ...
show more
(mod_security) mod_security (id:210492) triggered by 15.207.110.229 (IN/India/ec2-15-207-110-229.ap-south-1.compute.amazonaws.com): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Aug 29 03:00:32.634009 2025] [security2:error] [pid 1986171:tid 1986213] [client 15.207.110.229:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mogbox.net"] [uri "/sftp-config.json"] [unique_id "aLFQEKaBbBVAuym6TgISyAAAAA8"]
show less
Hacking
๐บ๐ธ
Starburst SysOp Team
2025-08-29 05:22:14
(1 year ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 229.110.207.15.rbl.malw ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 229.110.207.15.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-1)
show less
Hacking
๐บ๐ธ
octageeks.com
2025-08-29 04:07:07
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ซ๐ฎ
oh.mg
2025-08-29 03:16:46
(1 year ago)
[Fri Aug 29 05:16:44.698666 2025] [security2:error] [pid 379067:tid 379088] [client 15.207.110.229:0 ...
show more
[Fri Aug 29 05:16:44.698666 2025] [security2:error] [pid 379067:tid 379088] [client 15.207.110.229:0] [client 15.207.110.229] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mrman.net"] [uri "/sftp-config.json"] [unique_id "aLEbnFKRKNsi1rKA1l5HpgAAABM"], referer: http://mrman.net/sftp-config.json
[Fri Aug 29 05:16:45.627287 2025] [security2:error] [pid 379067:tid 379075] [client 15.207.110.229:0] [client 15.207.110.229] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Sco
...
show less
Bad Web Bot
Web App Attack
๐ท๐ธ
Smel
2025-08-29 02:22:08
(1 year ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐จ๐ญ
lufi
2025-08-28 23:49:41
(1 year ago)
2025-08-29 01:49:41 15.207.110.229: blacklisted Pattern: /sftp.json
...
Web Spam
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
findlab
2025-08-28 23:20:03
(1 year ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
Carltonfsck
2025-08-28 22:24:09
(1 year ago)
15.207.110.229 - - [28/Aug/2025:22:24:07 +0000] "GET /sftp.json HTTP/1.1" 404 49
15.207.110.229 - - ...
show more
15.207.110.229 - - [28/Aug/2025:22:24:07 +0000] "GET /sftp.json HTTP/1.1" 404 49
15.207.110.229 - - [28/Aug/2025:22:24:07 +0000] "GET /sftp-config.json HTTP/1.1" 404 49
...
show less
Hacking
Web App Attack
๐จ๐ฟ
huginet
2025-08-28 21:57:58
(1 year ago)
15.207.110.229 - - [28/Aug/2025:23:57:53 +0200] "GET /sftp.json HTTP/1.1" 404 82752 "https://huginet ...
show more
15.207.110.229 - - [28/Aug/2025:23:57:53 +0200] "GET /sftp.json HTTP/1.1" 404 82752 "https://huginet.net/sftp.json" "http://Mozilla/5.0 (Windows NT 5.2; rv:40.0) Gecko/20100101 Firefox/40.0"
15.207.110.229 - - [28/Aug/2025:23:57:56 +0200] "GET /sftp-config.json HTTP/1.1" 404 82759 "https://huginet.net/sftp-config.json" "http://Mozilla/5.0 (Windows NT 6.3; Win64; x64; Trident/7.0; Touch; ASU2JS; rv:11.0) like Gecko"
...
show less
DDoS Attack
FTP Brute-Force
Ping of Death
Phishing
Web Spam
Blog Spam
Spoofing
Brute-Force
Web App Attack
SSH
๐ช๐ธ
el-brujo
2025-08-28 21:19:26
(1 year ago)
Cloudflare WAF: Request Path: /sftp-config.json Request Query: Host: elhacker.net userAgent: http:/ ...
show more
Cloudflare WAF: Request Path: /sftp-config.json Request Query: Host: elhacker.net userAgent: http://Mozilla/5.0 (Windows NT 6.1; Trident/7.0; MDDRJS; rv:11.0) like Gecko Action: block Source: firewallManaged ASN Description: AMAZON-02 Country: IN Method: GET Timestamp: 2025-08-28T21:19:26Z ruleId: c2a2f414a67c409f90cccb6c5bba0215. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack