Anonymous
2026-09-10 19:39:40
(10 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-10 04:29:43
(1 day ago)
HTTP vulnerability scanning
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-08 22:03:23
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
๐ง๐ช
madeit
2026-08-19 11:47:49
(3 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 22:50:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:50:50.405344 2026] [security2:error] [pid 9873:tid 9890] [client 172.69.166.16:9711] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fconct.pwrcoupling.com"] [uri "/.git/config"] [unique_id "aoOQSrvgdR1owrjrnzH41AAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:19:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:19:52.192982 2026] [security2:error] [pid 30497:tid 30497] [client 172.69.166.16:11952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tunabay.com"] [uri "/.git/HEAD"] [unique_id "aoLSOJv-x7JTpjbQIVU0gwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Watch40x
2026-08-16 03:58:37
(3 weeks ago)
Automated report from Watch40x security system. Web application probing detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 21:54:07
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 17:54:02.061406 2026] [security2:error] [pid 21089:tid 21089] [client 172.69.166.16:13977] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fullyevil.com"] [uri "/.git/HEAD"] [unique_id "an-OeqUcd5f4Nmy3Yeu7RQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 21:33:26
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 17:33:19.635993 2026] [security2:error] [pid 6928:tid 6928] [client 172.69.166.16:11081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpking.com"] [uri "/.git/HEAD"] [unique_id "an-Jn2433xoWUT02GMoJvwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-14 19:22:27
(3 weeks ago)
[14/Aug/2026:22:22:26 +0300] -- 172.69.166.16 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[14/Aug/2026:22:22:26 +0300] -- 172.69.166.16 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 00:26:29
(4 weeks ago)
(mod_security) mod_security (id:949110) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.69.166.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 20:26:25.609522 2026] [security2:error] [pid 3010906:tid 3010906] [client 172.69.166.16:10770] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.theshitmykidsays.com"] [uri "/.git/config"] [unique_id "an5gsfz7LZDLBLckP3vtGgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-06 01:36:50
(1 month ago)
Attack detected: 172.69.166.16 [2026-08-06]
Categories: 18
--- xmlrpc abuse (77 hits) ---
172.69.166 ...
show more
Attack detected: 172.69.166.16 [2026-08-06]
Categories: 18
--- xmlrpc abuse (77 hits) ---
172.69.166.16 - - [19/Jun/2026:07:01:55 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "WordPress.com; https://wordpress.com"
172.69.166.16 - - [19/Jun/2026:07:02:37 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack/12.1; WordPress/6.4; http://site95293233.com"
172.69.166.16 - - [19/Jun/2026:07:03:09 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack/12.1; WordPress/6.3; http://site53078977.com"
172.69.166.16 - - [19/Jun/2026:07:03:41 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
172.69.166.16 - - [19/Jun/2026:07:04:23 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Anonymous
2026-07-22 00:46:12
(1 month ago)
Attack detected: 172.69.166.16 [2026-07-22]
Categories: 18
--- xmlrpc abuse (77 hits) ---
172.69.166 ...
show more
Attack detected: 172.69.166.16 [2026-07-22]
Categories: 18
--- xmlrpc abuse (77 hits) ---
172.69.166.16 - - [19/Jun/2026:07:01:55 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "WordPress.com; https://wordpress.com"
172.69.166.16 - - [19/Jun/2026:07:02:37 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack/12.1; WordPress/6.4; http://site95293233.com"
172.69.166.16 - - [19/Jun/2026:07:03:09 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack/12.1; WordPress/6.3; http://site53078977.com"
172.69.166.16 - - [19/Jun/2026:07:03:41 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
172.69.166.16 - - [19/Jun/2026:07:04:23 +0000] "POST /xmlrpc.php HTTP/2.0" 403 880 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Anonymous
2026-07-21 07:55:42
(1 month ago)
SQL Injection
SQL Injection
๐ซ๐ฎ
as211431.net
2026-07-14 12:37:28
(1 month ago)
Triggered Cloudflare WAF (linkMaze) from SG.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from SG.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot