π«π·
dynamix
2026-06-16 04:53:04
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-14 01:24:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.102.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.102.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 21:24:03.656458 2026] [security2:error] [pid 8028:tid 8028] [client 172.71.102.68:13875] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.butkiewiczfamilyfarm.com"] [uri "/.env.local"] [unique_id "agUkMwq1e-CLk-7ckU51ygAAAAM"], referer: https://www.google.com/search?q=cpanel.butkiewiczfamilyfarm.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-07 01:03:13
(1 month ago)
[Thu May 07 03:03:12.643401 2026] [authz_core:error] [pid 15820] [client 172.71.102.68:12490] AH0163 ...
show more
[Thu May 07 03:03:12.643401 2026] [authz_core:error] [pid 15820] [client 172.71.102.68:12490] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu May 07 03:03:12.661121 2026] [authz_core:error] [pid 15820] [client 172.71.102.68:12490] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu May 07 03:03:12.679821 2026] [authz_core:error] [pid 15820] [client 172.71.102.68:12490] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-29 13:06:25
(1 month ago)
[Wed Apr 29 15:06:23.904809 2026] [authz_core:error] [pid 8013] [client 172.71.102.68:11126] AH01630 ...
show more
[Wed Apr 29 15:06:23.904809 2026] [authz_core:error] [pid 8013] [client 172.71.102.68:11126] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Apr 29 15:06:24.246755 2026] [authz_core:error] [pid 8013] [client 172.71.102.68:11126] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Apr 29 15:06:24.583237 2026] [authz_core:error] [pid 8013] [client 172.71.102.68:11126] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-26 12:29:27
(1 month ago)
[Sun Apr 26 14:29:27.268639 2026] [authz_core:error] [pid 31423] [client 172.71.102.68:9388] AH01630 ...
show more
[Sun Apr 26 14:29:27.268639 2026] [authz_core:error] [pid 31423] [client 172.71.102.68:9388] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Apr 26 14:29:27.367675 2026] [authz_core:error] [pid 31423] [client 172.71.102.68:9388] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Apr 26 14:29:27.429198 2026] [authz_core:error] [pid 31423] [client 172.71.102.68:9388] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-04-09 07:30:24
(2 months ago)
[Thu Apr 09 09:30:22.899696 2026] [authz_core:error] [pid 27742] [client 172.71.102.68:9872] AH01630 ...
show more
[Thu Apr 09 09:30:22.899696 2026] [authz_core:error] [pid 27742] [client 172.71.102.68:9872] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
[Thu Apr 09 09:30:22.925826 2026] [authz_core:error] [pid 27742] [client 172.71.102.68:9872] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
[Thu Apr 09 09:30:23.008070 2026] [authz_core:error] [pid 27742] [client 172.71.102.68:9872] AH01630: client denied by server configuration: /etc/httpd/htdocs, referer: http://wolfgang-eitel.de/
...
show less
Web App Attack
Anonymous
2026-04-06 15:03:39
(2 months ago)
[Mon Apr 06 17:03:37.057205 2026] [authz_core:error] [pid 21171] [client 172.71.102.68:10090] AH0163 ...
show more
[Mon Apr 06 17:03:37.057205 2026] [authz_core:error] [pid 21171] [client 172.71.102.68:10090] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Apr 06 17:03:37.695224 2026] [authz_core:error] [pid 21171] [client 172.71.102.68:10090] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Apr 06 17:03:38.777086 2026] [authz_core:error] [pid 21171] [client 172.71.102.68:10090] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π©πͺ
FeG Deutschland
2026-03-19 22:21:19
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-02-06 18:08:51
(4 months ago)
[Fri Feb 06 19:08:50.757959 2026] [authz_core:error] [pid 9591] [client 172.71.102.68:9950] AH01630: ...
show more
[Fri Feb 06 19:08:50.757959 2026] [authz_core:error] [pid 9591] [client 172.71.102.68:9950] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Feb 06 19:08:50.804939 2026] [authz_core:error] [pid 9591] [client 172.71.102.68:9950] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri Feb 06 19:08:50.826370 2026] [authz_core:error] [pid 9591] [client 172.71.102.68:9950] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π¬π§
pinguin
2025-08-10 11:32:59
(10 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /phpinfo
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-05-11 08:40:19
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.102.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.102.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 11 04:40:14.489476 2025] [security2:error] [pid 2200888:tid 2200888] [client 172.71.102.68:45276] [client 172.71.102.68] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nursetammytalks.com"] [uri "/.git/config"] [unique_id "aCBibqDkAbmkPS9KZDRzygAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-06 22:56:01
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 172.71.102.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 172.71.102.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 18:55:57.406955 2025] [security2:error] [pid 64598:tid 64598] [client 172.71.102.68:25800] [client 172.71.102.68] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.yggdrasil.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.yggdrasil.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBqTfZuyD92hW50jrFQ8rAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Study Bitcoin π€
2025-05-02 15:08:40
(1 year ago)
Port probe to tcp/443 (https)
[srv125]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Study Bitcoin π€
2025-04-22 16:20:36
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
π³π±
Study Bitcoin π€
2025-04-19 17:38:49
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack