๐ท๐บ
DZBOT
2026-06-16 03:49:19
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
RootOPSOVH
2026-06-09 17:39:13
(2 weeks ago)
GET /wp-admin/install.php?step=1 | UA: http://rootops.ovh/wp-admin/install.php?step=1
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:47:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:47:50.337918 2026] [security2:error] [pid 2729:tid 2771] [client 172.70.247.104:11770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthlingtechnology.geoception.com"] [uri "/.git/config"] [unique_id "aiccZsEr22MGBm1zqbiCyAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-03 20:38:11
(2 weeks ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:12:02
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:11:58.012503 2026] [security2:error] [pid 4537:tid 4537] [client 172.70.247.104:11653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pearson-specter.com"] [uri "/.git/config"] [unique_id "ah8AznL4iKZss1yEIe3pbQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
RootOPSOVH
2026-06-02 00:09:16
(3 weeks ago)
GET /wp-admin/install.php?step=1 | UA: http://rootops.ovh/wp-admin/install.php?step=1
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 04:23:15
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 00:23:05.784036 2026] [security2:error] [pid 24876:tid 24876] [client 172.70.247.104:12435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.artfranz.com"] [uri "/.env.save"] [unique_id "ahPOqX9rloTR36H6BP8HrAAAABg"], referer: https://www.google.com/search?q=cpcalendars.artfranz.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-24 18:12:58
(4 weeks ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-05-17 09:49:23
(1 month ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 09:46:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 05:46:21.655748 2026] [security2:error] [pid 14724:tid 14766] [client 172.70.247.104:11319] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killyourattitude.com"] [uri "/.env.development"] [unique_id "agWZ7QeuHERmu7Brio_QEgAAAgs"], referer: https://www.google.com/search?q=killyourattitude.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-10 08:19:30
(1 month ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 07:40:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 03:40:43.490200 2026] [security2:error] [pid 15809:tid 15809] [client 172.70.247.104:9438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astoriaman.com"] [uri "/.git/config"] [unique_id "af7k-0mwTPs97eMrTfOdkAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 12:10:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.247.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 08:10:43.004299 2026] [security2:error] [pid 25888:tid 25888] [client 172.70.247.104:12018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icoinedthewordironesty.com"] [uri "/.git/config"] [unique_id "af3Sw3ifLoOL2qxZ11Q4wQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-05-04 17:04:33
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-05-04 14:25:47
(1 month ago)
Failed Wordpress Logins
Web App Attack