π«π·
dynamix
2026-10-09 01:52:14
(1 day ago)
Multiple WAF Violations
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-10-07 20:19:59
(2 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
π§πͺ
madeit
2026-09-24 03:43:04
(2 weeks ago)
Web App Attack
π§πͺ
madeit
2026-09-04 23:07:41
(1 month ago)
Web App Attack
π§πͺ
madeit
2026-08-21 14:58:07
(1 month ago)
Web App Attack
π©πͺ
acadeova
2026-05-31 01:22:16
(4 months ago)
π¨ Recon detected (nft drop)
SRC=172.69.59.163
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journ ...
show more
π¨ Recon detected (nft drop)
SRC=172.69.59.163
Observed=TCP dpt=80 in=enp0s6 ttl=56
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
π―π΅
S.O.B.A. Dev.
2026-05-08 16:35:26
(5 months ago)
Persistent port scanning or vulnerability scanning
Port Scan
Anonymous
2026-03-26 18:25:06
(6 months ago)
172.69.59.163 - - [26/Mar/2026:20:24:44 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content ...
show more
172.69.59.163 - - [26/Mar/2026:20:24:44 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/maileraso.php HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.69.59.163 - - [26/Mar/2026:20:24:49 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/cgi.php5 HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.69.59.163 - - [26/Mar/2026:20:24:56 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/madspotshell.php5 HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.69.59.163 - - [26/Mar/2026:20:25:00 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/.php HTTP/1.1" 404 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
172.69.59.163 - - [26/Mar/2026:20:25:06 +0200] "GET /.well-known/acme-challenge/cloud.php/wp-content/themes/finley/ucen.php HTTP/1.1" 404 124 "-" "Mozilla
...
show less
Brute-Force
Web App Attack
Anonymous
2025-08-05 17:59:41
(1 year ago)
[Tue Aug 05 19:59:40.093279 2025] [authz_core:error] [pid 23697] [client 172.69.59.163:27258] AH0163 ...
show more
[Tue Aug 05 19:59:40.093279 2025] [authz_core:error] [pid 23697] [client 172.69.59.163:27258] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Aug 05 19:59:40.220448 2025] [authz_core:error] [pid 23697] [client 172.69.59.163:27258] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Aug 05 19:59:40.346891 2025] [authz_core:error] [pid 23697] [client 172.69.59.163:27258] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π¬π§
pinguin
2025-07-31 18:43:05
(1 year ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Mac OS X 13_2) AppleWebKit/537.36 (KHTML, like Gecko) Safari/123.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πͺπΈ
Hugopvigo
2025-06-01 16:19:57
(1 year ago)
172.69.59.163 - - [01/Jun/2025:07:50:35 +0200] "GET /es/producto/uganda-10-gb-30-dias/?add-to-cart=8 ...
show more
172.69.59.163 - - [01/Jun/2025:07:50:35 +0200] "GET /es/producto/uganda-10-gb-30-dias/?add-to-cart=872 HTTP/1.1" 302 5044 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
172.69.59.163 - - [01/Jun/2025:09:54:27 +0200] "GET /es/internet-japon/?add-to-cart=978 HTTP/1.1" 302 5044 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
172.69.59.163 - - [01/Jun/2025:09:54:36 +0200] "GET /es/categoria-producto/paises/kirguistan/?add-to-cart=6453 HTTP/1.1" 302 1185 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
172.69.59.163 - - [01/Jun/2025:09:56:25 +0200] "GET /es/producto/oriente-medio-y-africa-del-norte-1-gb-7-dias/?add-to-cart=2072 HTTP/1.1" 302 5044 "-" "Scrapy/2.11.2 (+https://scrapy.org)"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
πΊπΈ
TPI-Abuse
2025-05-21 00:29:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.69.59.163 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.59.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 20 20:29:05.368995 2025] [security2:error] [pid 1185216:tid 1185216] [client 172.69.59.163:39696] [client 172.69.59.163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gibitdigital.com"] [uri "/.env"] [unique_id "aC0eUXFxBbWSU2xtFzyA9QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Study Bitcoin π€
2025-05-20 23:56:42
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-04-25 08:35:26
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 172.69.59.163 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 172.69.59.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 04:35:18.887658 2025] [security2:error] [pid 2511110:tid 2511110] [client 172.69.59.163:28718] [client 172.69.59.163] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.upskirtcrazy.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aAtJRoFxgtmNmhi7S0LkNgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Study Bitcoin π€
2025-02-10 18:26:39
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack