🇩🇪
maxpower
2026-09-14 04:55:36
(11 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 150.136.151.209 (US/United States/-): 1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 150.136.151.209 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 150.136.151.209 - - [14/Sep/2026:06:55:35 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-" host=studioegizi.it
show less
Port Scan
🇩🇪
maxpower
2026-09-14 04:40:34
(26 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 150.136.151.209 (US/United States/-): 1 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 150.136.151.209 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 150.136.151.209 - - [14/Sep/2026:06:40:30 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" "-" host=studioegizi.it
show less
Port Scan
🇫🇷
GoodOldTOS
2026-09-14 03:50:54
(1 hour ago)
Highly suspect IP
Hacking
Web App Attack
🇩🇪
Grossmann-Gruppe
2026-09-14 03:17:39
(1 hour ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
🇫🇮
as211431.net
2026-09-14 02:36:42
(2 hours ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-14 02:21:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 150.136.151.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.136.151.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 22:21:17.492549 2026] [security2:error] [pid 3811707:tid 3811715] [client 150.136.151.209:53812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nicholsinvest.com"] [uri "/wp-config.php.bak"] [unique_id "aqdaHbw6d-8wfjzDwfTBjgAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 01:41:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 150.136.151.209 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 150.136.151.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:41:31.015138 2026] [security2:error] [pid 1951346:tid 1951346] [client 150.136.151.209:54924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "engineeringarts.com"] [uri "/wp-config.php.bak"] [unique_id "aqdQy7ivsYjP0_e1xZq99AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-14 00:24:40
(4 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /api/session/properties | 2026-09-14 00:24 UTC
show less
Bad Web Bot
🇫🇷
sthoyer.de
2026-09-14 00:17:16
(4 hours ago)
Sep 14 02:17:10 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd: ...
show more
Sep 14 02:17:10 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=150.136.151.209 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=15070 DF PROTO=TCP SPT=55840 DPT=3000 WINDOW=62720 RES=0x00 SYN URGP=0
Sep 14 02:17:11 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=150.136.151.209 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=15071 DF PROTO=TCP SPT=55840 DPT=3000 WINDOW=62720 RES=0x00 SYN URGP=0
Sep 14 02:17:12 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=150.136.151.209 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=15072 DF PROTO=TCP SPT=55840 DPT=3000 WINDOW=62720 RES=0x00 SYN URGP=0
Sep 14 02:17:13 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=150.136.151.209 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=15073 DF PROTO=TCP SPT=55840 DPT=300
...
show less
Port Scan
🇧🇪
cmbplf
2026-09-13 23:01:59
(6 hours ago)
2.444 requests from abuseipdb.com blacklisted IP (10mos2w3d)
Brute-Force
Bad Web Bot
🇩🇪
findlab
2026-09-13 21:45:01
(7 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
🇫🇷
ELYAZ
2026-09-13 17:30:37
(11 hours ago)
(y3) Failed access -byebye- from 150.136.151.209 (US/United States/-): (CF_ENABLE)
Hacking
🇫🇷
Stara
2026-09-13 17:05:18
(12 hours ago)
Port scan detected - multiple connection attempts to various ports
Port Scan
Brute-Force
SSH
Anonymous
2026-09-13 15:02:14
(14 hours ago)
fail2ban:piguard2:14,18
Port Scan
Brute-Force
🇫🇷
masterguru
2026-09-13 14:31:29
(14 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 150.136.151.209 (US/United States/-): ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 150.136.151.209 (US/United States/-): 2 in the last 3600 secs (0-196)
show less
Hacking