๐บ๐ธ
jbettigole
2026-08-29 06:28:46
(1 day ago)
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/F ...
show more
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/FTP/Winbox/API/WWW) triggering escalating 5m/15m/1h/1d blacklist
show less
Brute-Force
Hacking
๐ช๐ธ
el-brujo
2026-08-23 16:56:26
(1 week ago)
23/Aug/2026:18:56:25.614251 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
23/Aug/2026:18:56:25.614251 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 162.158.106.194] ModSecurity: Warning. Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "703"] [id "920340"] [msg "Request Containing Content, but Missing Content-Type header"] [severity "NOTICE"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [hostname "el-hacker.org"] [uri "/vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php"] [unique_id "aosmObGjtkpH713uQE4HygAKxn4"]
...
show less
Hacking
Web App Attack
๐ฌ๐ง
pinguin
2026-06-29 03:38:08
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
abdubhai
2026-06-20 10:55:45
(2 months ago)
162.158.106.194 - - [20/Jun/2026
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-21 07:16:42
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.106.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.106.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 03:16:38.520589 2026] [security2:error] [pid 16788:tid 16788] [client 162.158.106.194:11391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.songforana.michaelsabbey.org"] [uri "/.env.vercel"] [unique_id "ag6xVsQCC9uaJomQ4wpUNwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 17:37:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.106.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.106.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 13:37:39.945523 2026] [security2:error] [pid 24819:tid 24819] [client 162.158.106.194:10669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.glencottagemusic.com"] [uri "/.git/config"] [unique_id "afzN46d_CIdObju8_x-afwAAAAQ"], referer: https://www.google.com/search?q=webdisk.glencottagemusic.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 09:51:20
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 162.158.106.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.106.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 05:50:56.192411 2026] [security2:error] [pid 16715:tid 16715] [client 162.158.106.194:12384] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||davesievers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davesievers.com"] [uri "/backup.sql"] [unique_id "afxggKFrs4jEb03HsnYuKQAAAAU"], referer: https://www.google.com/search?q=davesievers.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2025-09-15 03:10:13
(11 months ago)
162.158.106.194 - - [15/Sep/2025:08:10:11 +0500] "POST //xmlrpc.php HTTP/2.0" 200 278 "-" "Mozilla/5 ...
show more
162.158.106.194 - - [15/Sep/2025:08:10:11 +0500] "POST //xmlrpc.php HTTP/2.0" 200 278 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.106.194 - - [15/Sep/2025:08:10:12 +0500] "POST //xmlrpc.php HTTP/2.0" 200 278 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.106.194 - - [15/Sep/2025:08:10:12 +0500] "POST //xmlrpc.php HTTP/2.0" 200 254 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.106.194 - - [15/Sep/2025:08:10:12 +0500] "POST //xmlrpc.php HTTP/2.0" 200 254 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
162.158.106.194 - - [15/Sep/2025:08:10:13 +0500] "POST //xmlrpc.php HTTP/2.0" 200 278 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
Brute-Force
SSH
๐บ๐ธ
mawan
2025-09-14 01:01:53
(11 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-09-03 22:16:45
(11 months ago)
2025-09-03 17:38:31 /
Web App Attack
๐บ๐ธ
mawan
2025-09-01 15:19:02
(11 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-08-31 22:19:57
(11 months ago)
2025-08-31 17:21:32 /randkeyword.PhP7
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-08-29 22:15:52
(1 year ago)
2025-08-29 08:55:42 /docs/mbeans-descriptors-howto.html
Web App Attack
๐บ๐ธ
mawan
2025-08-10 15:34:07
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2025-07-31 13:37:19
(1 year ago)
wp admin page access attempt
...
Hacking
Web App Attack