๐ณ๐ฑ
homeshowdomain.nl
2026-06-22 21:59:12
(3 days ago)
Auto-ban: >3000 req/min op 2026-06-22
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-06-16 00:08:17
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 13:12:34
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 09:12:28.847027 2026] [security2:error] [pid 4110:tid 4110] [client 172.70.80.102:12837] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.smsindustries.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.smsindustries.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ai1XPI_MS_AxBGPmla0spAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-10 12:05:19
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-05 00:05:15
(3 weeks ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐ช๐ธ
librebit
2026-06-04 05:49:30
(3 weeks ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
๐บ๐ธ
mnsf
2026-06-03 18:06:17
(3 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 07:25:13
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 03:25:05.733525 2026] [security2:error] [pid 4205:tid 4205] [client 172.70.80.102:9751] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.molayemcapital.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.molayemcapital.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ahVK0R9P2YUp24K_ItHrmwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sandra361
2026-05-25 20:23:02
(1 month ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0 OUT= SRC=172.7 ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: GHOST_SCAN:IN=enp1s0 OUT= SRC=172.70.80.102 LEN=60 TOS=0x00 PREC=0x00 TTL=54 ID=5559 DF PROTO=TCP SPT=12782 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐ฉ๐ช
F242
2026-05-17 07:07:28
(1 month ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 03:58:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 23:58:12.596467 2026] [security2:error] [pid 3627307:tid 3627307] [client 172.70.80.102:9911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.edfisherco.com"] [uri "/.env.staging"] [unique_id "adcj1Ge8mwY2CqIsAJdm4QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 00:46:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 20:46:54.574600 2026] [security2:error] [pid 3101903:tid 3101903] [client 172.70.80.102:10527] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.calvarycavaliers.org"] [uri "/config/.env.local"] [unique_id "adb2_o91SnmCY3iK4K-kXgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 02:04:00
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 22:03:56.531628 2026] [security2:error] [pid 2106021:tid 2106021] [client 172.70.80.102:11334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.bees.properties"] [uri "/.env~"] [unique_id "adW3jOwSJ_ig8ZAdC-toDgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 12:22:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.102 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 08:22:47.722644 2026] [security2:error] [pid 1623384:tid 1623384] [client 172.70.80.102:11018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.starktigers75.com"] [uri "/config/.env.local"] [unique_id "adT3Fw1d7_Q0FXMXWx_B4QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-04-06 19:09:20
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /404.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot