๐บ๐ธ
TPI-Abuse
2026-07-30 06:53:34
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 152.89.168.16 (it-pom-server.powered-by.c1vhost ...
show more
(mod_security) mod_security (id:210492) triggered by 152.89.168.16 (it-pom-server.powered-by.c1vhosting.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 02:53:29.534516 2026] [security2:error] [pid 11359:tid 11369] [client 152.89.168.16:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.humanet.io"] [uri "/.env"] [unique_id "amr06baC5hK0OYnNI0jZKQAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 05:47:05
(2 hours ago)
http scanning for .env files
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 03:13:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 152.89.168.16 (it-pom-server.powered-by.c1vhost ...
show more
(mod_security) mod_security (id:210492) triggered by 152.89.168.16 (it-pom-server.powered-by.c1vhosting.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 23:13:08.533412 2026] [security2:error] [pid 1524530:tid 1524530] [client 152.89.168.16:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ard.global"] [uri "/.env"] [unique_id "amrBRNBmQZfcqOMrIX00-AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-07-30 03:11:39
(4 hours ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:20:14 - ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:20:14 -0300] "GET /i.php HTTP/1.1" 404 18193
152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:20:22 -0300] "GET /pi.php HTTP/1.1" 404 18193
152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:20:29 -0300] "GET /config.phpinfo HTTP/1.1" 404 18193
152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:20:38 -0300] "GET /admin/phpinfo.php HTTP/1.1" 404 18193
152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:20:46 -0300] "GET /.aws/credentials HTTP/1.1" 404 18193
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-07-30 01:01:59
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 152.89.168.16 (IT/Italy/it-pom-server.powered-b ...
show more
(mod_security) mod_security (id:210730) triggered by 152.89.168.16 (IT/Italy/it-pom-server.powered-by.c1vhosting.it): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ต๐ฑ
strefapi_com
2026-07-30 00:14:13
(7 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-07-30 00:11:27
(7 hours ago)
Web app vulnerability scanning detected. Evidence: 152.89.168.16 - - [30/Jul/2026:00:10:35 +0000] "G ...
show more
Web app vulnerability scanning detected. Evidence: 152.89.168.16 - - [30/Jul/2026:00:10:35 +0000] "GET /_profiler/phpinfo HTTP/1.1" 404 47365 "http://[DOMAIN]/_profiler/phpinfo" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
152.89.168.16 - - [30/Jul/2026:00:11:26 +0000] "GET /config.phpinfo HTTP/1.1" 404 47357 "http://[DOMAIN]/config.phpinfo" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Web App Attack
๐ฎ๐ฉ
soc-yk
2026-07-29 23:30:18
(8 hours ago)
Type: suspicious_network_activity
Risk: 75
Events: 9
Evidence:
- Persistent suspicious network acti ...
show more
Type: suspicious_network_activity
Risk: 75
Events: 9
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Threat escalation behavior observed
show less
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-29 21:03:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 152.89.168.16 (it-pom-server.powered-by.c1vhost ...
show more
(mod_security) mod_security (id:210492) triggered by 152.89.168.16 (it-pom-server.powered-by.c1vhosting.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:03:25.873067 2026] [security2:error] [pid 3886926:tid 3886926] [client 152.89.168.16:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.infinitewashing.com"] [uri "/app_dev.php/_profiler/open"] [unique_id "ampqnRFV8AdHpi5nUeLiFAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-07-29 17:19:57
(14 hours ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:19 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 152.89.168.16 162.158.116.60 - - [29/Jul/2026:14:19:49 -0300] "GET /info.php HTTP/1.1" 404 18193
show less
Bad Web Bot
๐ซ๐ฎ
as211431.net
2026-07-29 14:52:15
(17 hours ago)
Triggered Cloudflare WAF (firewallCustom) from IT.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 ...
show more
Triggered Cloudflare WAF (firewallCustom) from IT.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
Swiptly
2026-07-29 13:29:04
(18 hours ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐ซ๐ฎ
xyz.rip
2026-07-29 13:16:12
(18 hours ago)
WAF Violation
...
Hacking
Web App Attack
๐บ๐ธ
thieuleu
2026-07-29 13:09:58
(18 hours ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
Anonymous
2026-07-29 11:05:41
(20 hours ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (24/60 min)'; Requests=24
Port Scan