๐ฌ๐ง
pinguin
2026-06-18 20:18:22
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from SG.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-06-15 01:47:30
(4 days ago)
162.158.88.125 - - [15/Jun/2026:03:47:29 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
162.158.88.125 - - [15/Jun/2026:03:47:29 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.125 - - [15/Jun/2026:03:47:29 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.125 - - [15/Jun/2026:03:47:29 +0200] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.125 - - [15/Jun/2026:03:47:29 +0200] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 246 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
162.158.88.125 - - [15/Jun/2026:03:47:29 +0200] "GET //2018/wp-includes/wlwmanifest.xml HTTP
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 13:02:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 09:01:55.013874 2026] [security2:error] [pid 21011:tid 21011] [client 162.158.88.125:10717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cyber507.matronasoy.com"] [uri "/.env.local"] [unique_id "af8wQ6oQGjOfvMYnCZYVhwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 09:25:23
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 05:25:18.194328 2026] [security2:error] [pid 24423:tid 24423] [client 162.158.88.125:12237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.go-on.kreweofhyatt.com"] [uri "/.git/config"] [unique_id "af2r_oqmanUdZwE5YcTsBAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-02-10 01:18:02
(4 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.88.125
Observed=TCP dpt=80 in=enp0s6 ttl=54
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.88.125
Observed=TCP dpt=80 in=enp0s6 ttl=54
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
juutis
2026-01-28 00:16:52
(4 months ago)
162.158.88.125 - - [27/Jan/2026:23:46:21 +0100] "POST /hallinta/wp-login.php HTTP/1.0" 200 8352 "htt ...
show more
162.158.88.125 - - [27/Jan/2026:23:46:21 +0100] "POST /hallinta/wp-login.php HTTP/1.0" 200 8352 "https://www.maailmanaidspaiva.com/hallinta/wp-admin/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
162.158.88.125 - - [28/Jan/2026:01:14:42 +0100] "POST /hallinta/wp-login.php HTTP/1.0" 200 8352 "https://www.maailmanaidspaiva.com/hallinta/wp-admin/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
162.158.88.125 - - [28/Jan/2026:01:16:50 +0100] "POST /hallinta/wp-login.php HTTP/1.0" 200 8353 "https://www.maailmanaidspaiva.com/hallinta/wp-admin/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
show less
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-12-24 23:29:01
(5 months ago)
2025-12-24 04:52:38 /ex.php
2025-12-24 04:52:50 /price.php
2025-12-24 04:52:43 /v3.php
2025-12-24 04 ...
show more
2025-12-24 04:52:38 /ex.php
2025-12-24 04:52:50 /price.php
2025-12-24 04:52:43 /v3.php
2025-12-24 04:52:38 /zwso.php
2025-12-24 04:52:50 /ea3f.php
2025-12-24 04:52:45 /cwsd.php
2025-12-24 04:52:34 /npi.php
show less
Web App Attack
๐ฆ๐ท
crgim
2025-12-09 16:55:10
(6 months ago)
162.158.88.125 - - [09/Dec/2025:13:55:01 -0300] "GET /.env HTTP/1.1" 403 4169 "-" "Mozilla/5.0 (l9sc ...
show more
162.158.88.125 - - [09/Dec/2025:13:55:01 -0300] "GET /.env HTTP/1.1" 403 4169 "-" "Mozilla/5.0 (l9scan/2.0.33e27393e2431313e2838313; +https://leakix.net)"
show less
Hacking
Web App Attack
๐ฟ๐ฆ
agentics
2025-11-21 00:47:14
(6 months ago)
162.158.88.125 report :
DDoS Attack
FTP Brute-Force
Port Scan
Hacking
Spoofing
Brute-Force
Exploited Host
๐ณ๐ฑ
juutis
2025-10-07 12:41:07
(8 months ago)
Multiple WAF abuses - IP blocked
Hacking
Brute-Force
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-10-02 23:12:29
(8 months ago)
2025-10-02 23:04:27 /resources.zip
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2025-09-26 05:12:49
(8 months ago)
3 attacks on password grabbing URLs:
GET /.vscode/sftp.json~ HTTP/1.1
Hacking
๐จ๐ณ
ThreatBook.io
2025-09-18 00:05:10
(9 months ago)
2025-09-17 12:00:39 /resources.zip
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-09-16 00:28:40
(9 months ago)
2025-09-15 18:03:21 /metrics.zip
2025-09-15 18:03:22 /sharing.zip
Web App Attack
๐บ๐ธ
mawan
2025-08-30 02:25:19
(9 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack