๐ฎ๐ฉ
securejdprop
2026-07-21 03:40:20
(2 days ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐บ๐ธ
chrisj
2026-07-07 11:09:37
(2 weeks ago)
[Tue Jul 07 11:09:24.130275 2026] [proxy_fcgi:error] [pid 561142:tid 561163] [remote 162.158.88.103: ...
show more
[Tue Jul 07 11:09:24.130275 2026] [proxy_fcgi:error] [pid 561142:tid 561163] [remote 162.158.88.103:11641] AH01071: Got error 'Primary script unknown'
[Tue Jul 07 11:09:26.604815 2026] [proxy_fcgi:error] [pid 561142:tid 561164] [remote 162.158.88.103:11641] AH01071: Got error 'Primary script unknown'
[Tue Jul 07 11:09:36.502355 2026] [proxy_fcgi:error] [pid 561142:tid 561167] [remote 162.158.88.103:10503] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
chrisj
2026-07-05 20:02:09
(2 weeks ago)
[Sun Jul 05 20:02:07.007651 2026] [proxy_fcgi:error] [pid 515550:tid 515556] [remote 162.158.88.103: ...
show more
[Sun Jul 05 20:02:07.007651 2026] [proxy_fcgi:error] [pid 515550:tid 515556] [remote 162.158.88.103:10347] AH01071: Got error 'Primary script unknown'
[Sun Jul 05 20:02:07.807021 2026] [proxy_fcgi:error] [pid 515550:tid 515560] [remote 162.158.88.103:10347] AH01071: Got error 'Primary script unknown'
[Sun Jul 05 20:02:09.235726 2026] [proxy_fcgi:error] [pid 515550:tid 515557] [remote 162.158.88.103:10347] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
chrisj
2026-07-02 23:21:58
(2 weeks ago)
[Thu Jul 02 23:21:56.765308 2026] [proxy_fcgi:error] [pid 457167:tid 457207] [remote 162.158.88.103: ...
show more
[Thu Jul 02 23:21:56.765308 2026] [proxy_fcgi:error] [pid 457167:tid 457207] [remote 162.158.88.103:12393] AH01071: Got error 'Primary script unknown'
[Thu Jul 02 23:21:57.288055 2026] [proxy_fcgi:error] [pid 457167:tid 457210] [remote 162.158.88.103:12393] AH01071: Got error 'Primary script unknown'
[Thu Jul 02 23:21:57.811990 2026] [proxy_fcgi:error] [pid 457167:tid 457211] [remote 162.158.88.103:12393] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-01 13:34:13
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 09:33:40.272295 2026] [security2:error] [pid 27468:tid 27535] [client 162.158.88.103:37671] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||writeonce.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "writeonce.org"] [uri "/db.sql"] [unique_id "akUXNLZHJUlINE59FFBBEwAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-06-18 20:18:22
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-06-15 01:47:17
(1 month ago)
162.158.88.103 - - [15/Jun/2026:03:47:16 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 ...
show more
162.158.88.103 - - [15/Jun/2026:03:47:16 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.103 - - [15/Jun/2026:03:47:16 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.103 - - [15/Jun/2026:03:47:17 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.103 - - [15/Jun/2026:03:47:17 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.103 - - [15/Jun/2026:03:47:17 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 4
...
show less
Brute-Force
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-10 04:46:56
(1 month ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-05-24 03:53:58
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-09 06:44:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 02:44:12.745452 2026] [security2:error] [pid 6959:tid 6959] [client 162.158.88.103:13139] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swurgentvet.com"] [uri "/sftp-config.json"] [unique_id "af7XvE2quZdll0E-4nl5nQAAAAM"], referer: https://www.google.com/search?q=swurgentvet.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-05-08 17:09:05
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 14:53:22
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:53:18.300178 2026] [security2:error] [pid 27481:tid 27481] [client 162.158.88.103:14045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jonathanwilson.me"] [uri "/sftp-config.json"] [unique_id "af343lw80kQgeCNTmnCY5gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 11:24:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.103 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 07:24:11.642328 2026] [security2:error] [pid 6786:tid 6786] [client 162.158.88.103:13044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nue18.com"] [uri "/sftp-config.json"] [unique_id "af3H22ILzLNr5B8U9d7h1AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-03-24 01:26:28
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-03-23 01:20:16
(4 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack