πΊπΈ
TPI-Abuse
2026-06-08 18:43:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.17 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:43:17.631650 2026] [security2:error] [pid 2729:tid 2760] [client 172.68.151.17:12515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultratecnia.onernet.com"] [uri "/.git/config"] [unique_id "aicNRcEr22MGBm1zqbhl7gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
acadeova
2026-06-05 09:07:32
(3 days ago)
π¨ Recon detected (nft drop)
SRC=172.68.151.17
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journ ...
show more
π¨ Recon detected (nft drop)
SRC=172.68.151.17
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
π¬π§
pinguin
2026-03-20 22:05:12
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /%2Fproducts
UA: curl/8.7.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π«π·
dynamix
2026-03-18 01:40:27
(2 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-03-09 06:09:50
(2 months ago)
Aggressive web scan
Web App Attack
π«π·
Baking333
2026-03-01 17:52:41
(3 months ago)
[redacted] 172.68.151.17 - - [01/Mar/2026:18:52:39 +0100] "GET /root/.aws/credentials HTTP/2.0" 301 ...
show more
[redacted] 172.68.151.17 - - [01/Mar/2026:18:52:39 +0100] "GET /root/.aws/credentials HTTP/2.0" 301 208 "-" "curl/8.7.1" [redacted] 172.68.151.17 - - [01/Mar/2026:18:52:39 +0100] "GET /fr/root/.aws/credentials/ HTTP/2.0" 404 24868 "-" "curl/8.7.1"
show less
Bad Web Bot
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-02-25 22:47:26
(3 months ago)
(CT) IP 172.68.151.17 (FR/France/Γle-de-France/Paris/-/[AS13335 CLOUDFLARENET]) found to have 108 co ...
show more
(CT) IP 172.68.151.17 (FR/France/Γle-de-France/Paris/-/[AS13335 CLOUDFLARENET]) found to have 108 connections (0-srv1)
show less
Hacking
π«π·
Baking333
2026-02-14 08:44:38
(3 months ago)
[redacted] 172.68.151.17 - - [14/Feb/2026:09:44:36 +0100] "GET /fr/.[redacted]/ HTTP/2.0" 404 25128 ...
show more
[redacted] 172.68.151.17 - - [14/Feb/2026:09:44:36 +0100] "GET /fr/.[redacted]/ HTTP/2.0" 404 25128 "-" "curl/8.7.1" [redacted] 172.68.151.17 - - [14/Feb/2026:09:44:37 +0100] "GET /.[redacted] HTTP/2.0" 301 101 "-" "curl/8.7.1"
show less
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-01-28 18:51:49
(4 months ago)
172.68.151.17 - - [28/Jan/2026:20:51:38 +0200] "GET /wp-admin/network/xmrlpc.php?p= HTTP/1.1" 404 28 ...
show more
172.68.151.17 - - [28/Jan/2026:20:51:38 +0200] "GET /wp-admin/network/xmrlpc.php?p= HTTP/1.1" 404 2868 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
172.68.151.17 - - [28/Jan/2026:20:51:48 +0200] "GET /wp-includes/rest-api/endpoints/ HTTP/1.1" 404 2869 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
πΊπΈ
sumnone
2026-01-23 09:41:05
(4 months ago)
Port probing on unauthorized port 8080
Port Scan
Hacking
Exploited Host
π¬π§
pinguin
2026-01-11 05:27:56
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /phpinfo.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π«π·
dynamix
2026-01-06 19:59:48
(5 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
mawan
2025-12-31 04:46:38
(5 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
πͺπΈ
el-brujo
2025-12-28 09:40:48
(5 months ago)
28/Dec/2025:10:40:47.759004 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Dec/2025:10:40:47.759004 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.68.151.17] ModSecurity: Warning. Matched phrase "database.yml" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: database.yml found within REQUEST_FILENAME: /config/database.yml"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "cloudflare.elhacker.net"] [uri "/config/database.yml"] [unique_id "aVD7H3k-bKCFeoNf4MchvwAEaRQ"]
...
show less
Hacking
Web App Attack