๐บ๐ธ
wimaxnz
2026-06-04 07:25:44
(3 days ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
Anonymous
2026-05-21 14:05:02
(2 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-14 22:05:20
(3 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-13.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-04-21 22:05:02
(1 month ago)
Auto-ban: >3000 req/min op 2026-04-21
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-03-31 17:06:31
(2 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-03-30 16:06:46
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 07:19:49
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 26 03:19:20.959016 2026] [security2:error] [pid 3346:tid 3429] [client 162.158.79.139:9619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.baronlongford.com"] [uri "/.env.local"] [unique_id "acTd-Ib3XSmT9wcd7sE90gAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-26 00:06:00
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 20:05:52.490418 2026] [security2:error] [pid 7891:tid 7891] [client 162.158.79.139:12635] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anxo.org"] [uri "/.env_secret"] [unique_id "acR4YOTGnacHp2i0VAqPegAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 17:04:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 13:04:34.493398 2026] [security2:error] [pid 22990:tid 22990] [client 162.158.79.139:13250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.rndplumbing.com"] [uri "/.env.container"] [unique_id "acQVogo6EtEMELBLdeeAVAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-25 15:27:13
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.79.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 11:25:55.599568 2026] [security2:error] [pid 15234:tid 15234] [client 162.158.79.139:11393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.naturev.net"] [uri "/.env.local.backup"] [unique_id "acP-g9hexIw9EotQ911lQAAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-01-21 20:28:48
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
no1knows.com
2025-11-20 21:18:18
(6 months ago)
2025/11/20 21:18:15 [error] 1034284#1034284: *53328 FastCGI sent in stderr: "Primary script unknown" ...
show more
2025/11/20 21:18:15 [error] 1034284#1034284: *53328 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 162.158.79.139, server: _, request: "GET /new4.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com", referrer: "https://www.bing.com/"
2025/11/20 21:18:15 [error] 1034284#1034284: *53328 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 162.158.79.139, server: _, request: "GET /bolt.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com", referrer: "https://www.google.fr/"
2025/11/20 21:18:15 [error] 1034284#1034284: *53328 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 162.158.79.139, server: _, request: "GET /ava.php HTTP/1.1", upstream: "fastcgi://unix:/run/php-fpm/www.sock:", host: "no1knows.com", referrer: "https://duckduckgo.com/"
...
show less
Brute-Force
Bad Web Bot
Anonymous
2025-09-11 10:41:27
(8 months ago)
[Thu Sep 11 12:41:26.813255 2025] [authz_core:error] [pid 21798] [client 162.158.79.139:40206] AH016 ...
show more
[Thu Sep 11 12:41:26.813255 2025] [authz_core:error] [pid 21798] [client 162.158.79.139:40206] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Sep 11 12:41:26.913769 2025] [authz_core:error] [pid 21798] [client 162.158.79.139:40206] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Sep 11 12:41:27.015073 2025] [authz_core:error] [pid 21798] [client 162.158.79.139:40206] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฉ๐ช
Blexyel
2025-09-06 22:56:44
(9 months ago)
162.158.79.139 - - [07/Sep/2025:00:56:43 +0200] "GET /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
162.158.79.139 - - [07/Sep/2025:00:56:43 +0200] "GET /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2025-08-05 18:35:31
(10 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot