๐ฏ๐ต
S.O.B.A. Dev.
2026-09-20 11:35:11
(10 hours ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฉ๐ช
brechtr
2026-09-16 02:16:28
(4 days ago)
[Press84-BanHammer] bad username โ Sourced from: press84.com โ Request: POST /blog/wp-login.php
Brute-Force
๐ณ๐ฑ
BlueWire Hosting
2026-09-15 16:43:34
(5 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-13 06:34:17
(1 week ago)
162.158.88.40 - - [13/Sep/2026:06:34:16 +0000] "GET /.env.save HTTP/1.1" 302 4484 "https://www.googl ...
show more
162.158.88.40 - - [13/Sep/2026:06:34:16 +0000] "GET /.env.save HTTP/1.1" 302 4484 "https://www.google.com/search?q=www.pensagarden.com" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.6422.113 Mobile Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-10 19:00:19
(1 week ago)
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-09 06:10:39
(1 week ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 22:36:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:36:07.320502 2026] [security2:error] [pid 7438:tid 7438] [client 162.158.88.40:9633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nagareinkpaper.com"] [uri "/.git/HEAD"] [unique_id "aoOM1xGPW8MO1bomDlvftwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:59:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:59:50.001678 2026] [security2:error] [pid 9914:tid 9914] [client 162.158.88.40:10273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wcvfra.net"] [uri "/.git/config"] [unique_id "aoLNhqrLnmZUGzOihebAIgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 02:44:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 22:43:52.986897 2026] [security2:error] [pid 25100:tid 25100] [client 162.158.88.40:10429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.emeraldhighlands.org"] [uri "/.git/config"] [unique_id "aoJ1aPEeOGeQDRW9GgQGfQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 00:13:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 20:12:56.163282 2026] [security2:error] [pid 23227:tid 23240] [client 162.158.88.40:13435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lancasterdesignercraftsmen.org"] [uri "/.git/config"] [unique_id "aoJSCDTNFvvGrCapibQygwAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:04:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.88.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:04:13.843263 2026] [security2:error] [pid 30978:tid 30984] [client 162.158.88.40:13189] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pizzadlux.com"] [uri "/.git/config"] [unique_id "aoFS3SaG0mm0q8dHph1stAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-07-25 11:39:17
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ธ๐ฌ
pusathosting.com
2026-07-24 12:54:02
(1 month ago)
24ds22 bruteforce
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-06-07 23:52:26
(3 months ago)
Triggered Cloudflare WAF (linkMaze) from SG.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from SG.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
acadeova
2026-05-31 17:56:38
(3 months ago)
๐จ Recon detected (nft drop)
SRC=162.158.88.40
Observed=TCP dpt=80 in=enp0s6 ttl=54
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=162.158.88.40
Observed=TCP dpt=80 in=enp0s6 ttl=54
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan