๐ฌ๐ง
pinguin
2026-06-04 05:48:59
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /debug/default/view
UA: Mozilla/5.0 (l9scan/2.0.8393e26323e28313e2430313; +https://leakix.net)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-04 04:49:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 00:49:29.183059 2026] [security2:error] [pid 14766:tid 14766] [client 172.70.248.97:13852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scperu.net"] [uri "/.git/config"] [unique_id "aiED2Sf5rEzSkfKJlkVKKQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 13:44:55
(1 day ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 21:16:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 17:16:30.967220 2026] [security2:error] [pid 19189:tid 19210] [client 172.70.248.97:11864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "retrieversocal.com"] [uri "/.git/config"] [unique_id "ah9ILhahZWVomdqlbwuqUAAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 19:55:46
(2 days ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/install.php
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 17:05:20
(2 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:54:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:54:07.473409 2026] [security2:error] [pid 27689:tid 27689] [client 172.70.248.97:10132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "micahgartman.com"] [uri "/.git/config"] [unique_id "ah7uj2aAQsXMpBMreJxVOgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 11:09:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 07:09:11.332060 2026] [security2:error] [pid 22810:tid 22810] [client 172.70.248.97:14282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bioemperor.com"] [uri "/.git/config"] [unique_id "ah6515NV2gcZ44IpHVSbHwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-31 09:18:31
(4 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 11:41:17
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 07:41:09.581940 2026] [security2:error] [pid 17292:tid 17311] [client 172.70.248.97:11797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.priyom.us"] [uri "/.env.vercel"] [unique_id "ahl7VWh57-Mngulgnb1rugAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-26 19:18:12
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
octageeks.com
2026-05-26 04:07:05
(1 week ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐ฉ๐ช
bescared
2026-05-13 10:41:31
(3 weeks ago)
F2B - Malicious activity detected. URL Probing. -151302cd-
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-07 00:05:22
(1 month ago)
Scanning/Probing (22)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 00:40:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.248.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 20:40:29.823978 2026] [security2:error] [pid 30021:tid 30021] [client 172.70.248.97:10155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qatest.soudertonbigred.org"] [uri "/.env.local.backup"] [unique_id "adMA_dahEe-RwK2razFWRAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack