๐ฉ๐ช
acadeova
2026-08-02 20:29:12
(3 weeks ago)
๐จ Recon detected (nft drop)
SRC=172.68.10.28
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journa ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.10.28
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฌ๐ง
sandra361
2026-05-27 22:44:02
(2 months ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172 ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0f0 OUT= SRC=172.68.10.28 LEN=60 TOS=0x00 PREC=0x00 TTL=52 ID=39805 DF PROTO=TCP SPT=12388 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐ท๐บ
DZBOT
2026-05-21 01:46:05
(3 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
acadeova
2026-05-08 06:46:10
(3 months ago)
๐จ Recon detected (nft drop)
SRC=172.68.10.28
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journa ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.10.28
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฉ๐ช
psauxit
2026-04-30 01:20:40
(3 months ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking
Anonymous
2026-03-25 08:53:55
(4 months ago)
[Wed Mar 25 09:53:50.131053 2026] [authz_core:error] [pid 19227] [client 172.68.10.28:10816] AH01630 ...
show more
[Wed Mar 25 09:53:50.131053 2026] [authz_core:error] [pid 19227] [client 172.68.10.28:10816] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://www.google.it/
[Wed Mar 25 09:53:53.052805 2026] [authz_core:error] [pid 19227] [client 172.68.10.28:10816] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://duckduckgo.com/
[Wed Mar 25 09:53:53.744152 2026] [authz_core:error] [pid 19227] [client 172.68.10.28:10816] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: https://t.co/
...
show less
Web App Attack
Anonymous
2026-03-06 21:29:42
(5 months ago)
172.68.10.28 - - [06/Mar/2026:13:22:26 -0500] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 30 ...
show more
172.68.10.28 - - [06/Mar/2026:13:22:26 -0500] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 301 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
172.68.10.28 - - [06/Mar/2026:14:40:03 -0500] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 301 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
172.68.10.28 - - [06/Mar/2026:14:51:59 -0500] "GET /wordpress/wp-admin/setup-config.php HTTP/1.1" 301 555 "-" "http://cyberelements.ch/wordpress/wp-admin/setup-config.php"
172.68.10.28 - - [06/Mar/2026:15:32:56 -0500] "GET /wp-admin/setup-config.php HTTP/1.1" 301 535 "-" "http://cyberelements.ch/wp-admin/setup-config.php"
172.68.10.28 - - [06/Mar/2026:16:29:42 -0500] "GET /wp-admin/setup-config.php HTTP/1.1" 301 535 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36"
...
show less
Brute-Force
Anonymous
2026-01-23 10:38:09
(7 months ago)
FortiWeb WAF: 20 attacks detected. Threat Score: 5000. Types: Client Management(10), GEO IP(10). Ori ...
show more
FortiWeb WAF: 20 attacks detected. Threat Score: 5000. Types: Client Management(10), GEO IP(10). Origin: Russian Federation.
show less
Web App Attack
๐ฌ๐ง
pinguin
2026-01-12 21:48:27
(7 months ago)
Triggered Cloudflare WAF (firewallManaged) from RU.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from RU.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Linux; arm_64; Android 12; CPH2205) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 YaBrowser/23.3.3.86.00 SA/3 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-01-07 04:08:46
(7 months ago)
[Wed Jan 07 05:08:45.545261 2026] [authz_core:error] [pid 31271] [client 172.68.10.28:12665] AH01630 ...
show more
[Wed Jan 07 05:08:45.545261 2026] [authz_core:error] [pid 31271] [client 172.68.10.28:12665] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
[Wed Jan 07 05:08:45.616219 2026] [authz_core:error] [pid 31271] [client 172.68.10.28:12665] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
[Wed Jan 07 05:08:45.687323 2026] [authz_core:error] [pid 31271] [client 172.68.10.28:12665] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-01-07 03:05:06
(7 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
Anonymous
2026-01-06 16:50:58
(7 months ago)
[Tue Jan 06 17:50:54.677658 2026] [authz_core:error] [pid 27548] [client 172.68.10.28:11515] AH01630 ...
show more
[Tue Jan 06 17:50:54.677658 2026] [authz_core:error] [pid 27548] [client 172.68.10.28:11515] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jan 06 17:50:57.199955 2026] [authz_core:error] [pid 27548] [client 172.68.10.28:11515] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jan 06 17:50:57.309083 2026] [authz_core:error] [pid 27548] [client 172.68.10.28:11515] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฌ๐ง
pinguin
2025-12-15 21:28:52
(8 months ago)
Triggered Cloudflare WAF (firewallManaged) from RU.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from RU.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Linux; arm_64; Android 12; CPH2205) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 YaBrowser/23.3.3.86.00 SA/3 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
mnsf
2025-11-08 10:05:06
(9 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
Anonymous
2025-10-30 00:06:43
(9 months ago)
[Thu Oct 30 01:06:41.821282 2025] [authz_core:error] [pid 32332] [client 172.68.10.28:9783] AH01630: ...
show more
[Thu Oct 30 01:06:41.821282 2025] [authz_core:error] [pid 32332] [client 172.68.10.28:9783] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
[Thu Oct 30 01:06:42.011201 2025] [authz_core:error] [pid 32332] [client 172.68.10.28:9783] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
[Thu Oct 30 01:06:42.083640 2025] [authz_core:error] [pid 32332] [client 172.68.10.28:9783] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
...
show less
Web App Attack