Anonymous
2026-09-22 20:50:03
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ง๐ช
madeit
2026-09-14 12:59:24
(1 week ago)
Web App Attack
๐ง๐ช
madeit
2026-08-29 14:34:14
(3 weeks ago)
Web App Attack
๐ง๐พ
lns.bz
2026-08-29 01:38:05
(3 weeks ago)
Too many 404 requests [BY]
Web App Attack
Anonymous
2026-07-13 11:29:04
(2 months ago)
[Mon Jul 13 13:29:03.419203 2026] [authz_core:error] [pid 13552] [client 172.70.80.196:10173] AH0163 ...
show more
[Mon Jul 13 13:29:03.419203 2026] [authz_core:error] [pid 13552] [client 172.70.80.196:10173] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jul 13 13:29:03.543742 2026] [authz_core:error] [pid 13552] [client 172.70.80.196:10173] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jul 13 13:29:03.665463 2026] [authz_core:error] [pid 13552] [client 172.70.80.196:10173] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 03:19:13
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 23:19:10.630452 2026] [security2:error] [pid 4790:tid 4790] [client 172.70.80.196:13490] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.stevestoyostove.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.stevestoyostove.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akXYruI9KoiJWLNos0thlgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-07-01 13:32:09
(2 months ago)
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /ingfo.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-30 14:30:42
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 10:30:33.765484 2026] [security2:error] [pid 31700:tid 31700] [client 172.70.80.196:11459] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.globaldentalservices.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.globaldentalservices.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akPTCZCo2PHRX64fca04dAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BiancaNL
2026-06-29 21:19:13
(2 months ago)
Fail2Ban: jail=nginx-exploit-probes on <fqdn> (port=<port>)
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 22:00:16
(3 months ago)
Auto-ban: >3000 req/min op 2026-06-10
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 11:50:10
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:50:05.643514 2026] [security2:error] [pid 14326:tid 14332] [client 172.70.80.196:13533] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.jeflis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.jeflis.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aif97dl-gtKpK_MPLyvsqQAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-06-03 01:39:52
(3 months ago)
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /166.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-20 11:51:09
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 07:51:05.501340 2026] [security2:error] [pid 360:tid 360] [client 172.70.80.196:10508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.stevestoyostove.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.stevestoyostove.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ag2gKec8JMPSWmIaTvVdgwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 20:13:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 16:13:42.062323 2026] [security2:error] [pid 2615044:tid 2615044] [client 172.70.80.196:14331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.geriking.com"] [uri "/.env~"] [unique_id "ada29oRc3gqTVuxhTd0VPwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 09:06:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.80.196 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 05:06:38.131331 2026] [security2:error] [pid 2351856:tid 2351856] [client 172.70.80.196:10966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sr.handyrehab.com"] [uri "/backend/.env"] [unique_id "adYanqJ3d_BUrAud2zcdIQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack