๐ณ๐ฑ
COMPLEX
2026-06-10 00:19:46
(1 day ago)
Unsolicited TCP traffic | Action: DROP | Port 8443
Brute-Force
๐ฌ๐ง
pinguin
2026-06-04 06:14:50
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: okhttp/5.3.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
sandra361
2026-05-29 14:47:01
(1 week ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=162 ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=162.158.79.11 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=6793 DF PROTO=TCP SPT=11003 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-15 11:47:14
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:47:06.027360 2026] [security2:error] [pid 2924:tid 2924] [client 162.158.79.11:12907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ageh.com"] [uri "/.env.backup"] [unique_id "agcHuhG5gktLSYlvO_vlNAAAAC4"], referer: https://www.google.com/search?q=ageh.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:05:28
(1 month ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐บ๐ธ
mawan
2026-04-13 09:04:13
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 14:05:25
(2 months ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-05 00:05:18
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-02 14:05:18
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐ฉ๐ช
Blexyel
2026-04-02 04:51:44
(2 months ago)
162.158.79.11 - - [02/Apr/2026:04:51:39 +0000] "GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
162.158.79.11 - - [02/Apr/2026:04:51:39 +0000] "GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404 13 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-31 01:05:55
(2 months ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 04:26:39
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 00:26:25.242075 2026] [security2:error] [pid 29406:tid 29406] [client 162.158.79.11:13386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.wholesaleglassjars.com"] [uri "/.env.example"] [unique_id "acYG8eJxVbt_RGTJ-S6__AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 04:10:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 00:10:04.070952 2026] [security2:error] [pid 28709:tid 28709] [client 162.158.79.11:13253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "97films.media"] [uri "/.env.development"] [unique_id "acYDHGF29049tvkcylBwBwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 01:06:20
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 21:06:07.432507 2026] [security2:error] [pid 24096:tid 24096] [client 162.158.79.11:10211] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aimer.es"] [uri "/backend/.env"] [unique_id "acXX_1Dl_YHT79UV3uD7mwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-27 00:05:43
(2 months ago)
Scanning/Probing (22)
Brute-Force
Web App Attack