๐บ๐ธ
TPI-Abuse
2026-06-27 17:03:54
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 13:03:38.311634 2026] [security2:error] [pid 11259:tid 11259] [client 172.68.151.95:13860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "achillespress.com"] [uri "/.env.backup"] [unique_id "akACanAQLOc_JI88IotSagAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-25 02:31:43
(2 days ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.68.151.95 (FR/France/-): 1 in the last 46 ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.68.151.95 (FR/France/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 172.68.151.95 - - [25/Jun/2026:05:29:37 +0300] "GET /login_up.php HTTP/2.0" 200 27714 "-" "Go-http-client/1.1" "2001:41d0:305:2100::30e"'/login_up.php' '' '/opt/psa/admin/htdocs'
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-09 05:04:22
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:04:15.619491 2026] [security2:error] [pid 19287:tid 19293] [client 172.68.151.95:10570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cookmanufacturinggroup.com"] [uri "/.git/config"] [unique_id "aieez5KO57l_MYFdYNEVCwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 01:17:15
(3 weeks ago)
[Fri Jun 05 03:17:14.420560 2026] [authz_core:error] [pid 23397] [client 172.68.151.95:10819] AH0163 ...
show more
[Fri Jun 05 03:17:14.420560 2026] [authz_core:error] [pid 23397] [client 172.68.151.95:10819] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jun 05 03:17:14.589749 2026] [authz_core:error] [pid 23397] [client 172.68.151.95:10819] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Jun 05 03:17:14.799293 2026] [authz_core:error] [pid 23397] [client 172.68.151.95:10819] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-06-03 10:14:58
(3 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-05-25 01:54:17
(1 month ago)
[Mon May 25 03:54:15.334987 2026] [authz_core:error] [pid 13509] [client 172.68.151.95:10819] AH0163 ...
show more
[Mon May 25 03:54:15.334987 2026] [authz_core:error] [pid 13509] [client 172.68.151.95:10819] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon May 25 03:54:15.582013 2026] [authz_core:error] [pid 13509] [client 172.68.151.95:10819] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon May 25 03:54:15.793838 2026] [authz_core:error] [pid 13509] [client 172.68.151.95:10819] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-05-23 12:54:07
(1 month ago)
172.68.151.95 - - [23/May/2026:14:54:06 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 186 " ...
show more
172.68.151.95 - - [23/May/2026:14:54:06 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.68.151.95 - - [23/May/2026:14:54:06 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.68.151.95 - - [23/May/2026:14:54:07 +0200] "GET /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.68.151.95 - - [23/May/2026:14:54:07 +0200] "GET /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404 186 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.68.151.95 - - [23/May/2026:14:54:07 +0200] "GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 20:27:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.151.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.151.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 16:27:33.110559 2026] [security2:error] [pid 32696:tid 32696] [client 172.68.151.95:9393] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.3-6trucking.com"] [uri "/.env.dev"] [unique_id "agTeta9Hqqp3qpm3qTdrkQAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-11 21:59:33
(1 month ago)
Auto-ban: >3000 req/min op 2026-05-11
Web App Attack
SSH
Hacking
๐ฏ๐ต
S.O.B.A. Dev.
2026-04-17 10:20:51
(2 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ฉ๐ช
netclix.gr
2026-04-17 06:21:15
(2 months ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.68.151.95 (FR/France/-): 1 in the last 46 ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.68.151.95 (FR/France/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 172.68.151.95 - - [17/Apr/2026:09:00:55 +0300] "POST /login_up.php HTTP/2.0" 200 27736 "-" "Go-http-client/1.1" "2001:41d0:305:2100::30e"'/login_up.php' '' '/opt/psa/admin/htdocs'
show less
Port Scan
๐ฌ๐ง
pinguin
2026-04-05 07:57:34
(2 months ago)
Triggered Cloudflare WAF (linkMaze) from FR.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF (linkMaze) from FR.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (GET method)
Endpoint: /wp-content/plugins/hellopress/wp_filemanager.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-03-31 15:48:14
(2 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-197)
Hacking
๐ฉ๐ช
Starburst SysOp Team
2026-03-27 23:36:35
(2 months ago)
(CT) IP 172.68.151.95 (FR/France/Paris Department/Paris/-/[AS13335 Cloudflare, Inc.]) found to have ...
show more
(CT) IP 172.68.151.95 (FR/France/Paris Department/Paris/-/[AS13335 Cloudflare, Inc.]) found to have 101 connections (0-nue6-2)
show less
Hacking
๐บ๐ธ
mnsf
2026-03-20 14:08:25
(3 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack