๐ฉ๐ช
palla89
2026-06-25 10:48:31
(4 days ago)
(wordpress) Failed wordpress login from 172.71.130.221 (FR/France/-)
Brute-Force
๐ฉ๐ช
netclix.gr
2026-05-12 13:47:09
(1 month ago)
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.71.130.221 (FR/France/-): 1 in the last 4 ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Go-http-client 172.71.130.221 (FR/France/-): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 172.71.130.221 - - [12/May/2026:16:03:23 +0300] "GET /login_up.php HTTP/2.0" 200 27691 "-" "Go-http-client/1.1" "2001:41d0:305:2100::30e"'/login_up.php' '' '/opt/psa/admin/htdocs'
show less
Port Scan
๐บ๐ธ
Furry Network Services
2026-03-29 18:28:34
(2 months ago)
Blocked by UFW [8080/tcp] | SPT: 10396 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sef ...
show more
Blocked by UFW [8080/tcp] | SPT: 10396 | TTL: 52 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
MPL
2026-03-21 01:07:32
(3 months ago)
tcp/443 (10 or more attempts)
Port Scan
๐ฌ๐ง
pinguin
2026-03-20 22:05:14
(3 months ago)
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /%2Fswagger%2F2ejson
UA: curl/8.7.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-08-19 13:15:55
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
thefoofighter
2025-07-19 07:45:49
(11 months ago)
[Sat Jul 19 07:45:45.854122 2025] [:error] [pid 537585] [client 172.71.130.221:16696] [client 172.71 ...
show more
[Sat Jul 19 07:45:45.854122 2025] [:error] [pid 537585] [client 172.71.130.221:16696] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cathalmcnally.com"] [uri "/.env.prod"] [unique_id "aHtNKVZEW52PdxIhFFlQbgAAAAQ"]
[Sat Jul 19 07:45:49.036377 2025] [:error] [pid 537585] [client 172.71.130.221:16696] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWA
...
show less
Bad Web Bot
Web App Attack
Anonymous
2025-07-17 16:13:39
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
thefoofighter
2025-05-03 21:07:32
(1 year ago)
[Sat May 03 21:07:28.223724 2025] [:error] [pid 2810372] [client 172.71.130.221:45056] [client 172.7 ...
show more
[Sat May 03 21:07:28.223724 2025] [:error] [pid 2810372] [client 172.71.130.221:45056] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cathalmcnally.com"] [uri "/old/.env"] [unique_id "aBaFkJb3GO14RX3Rf_ubgAAAAAM"]
[Sat May 03 21:07:32.009476 2025] [:error] [pid 2810372] [client 172.71.130.221:45056] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OW
...
show less
Bad Web Bot
Web App Attack
Anonymous
2025-04-26 19:39:09
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-04-23 08:19:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 04:19:25.073830 2025] [security2:error] [pid 221740:tid 221740] [client 172.71.130.221:30202] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.upskirtcrazy.com"] [uri "/main/.env"] [unique_id "aAiijY5unQclIWpMQCMgXAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-23 02:23:10
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-04-22 20:15:50
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.130.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.130.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 16:15:43.620338 2025] [security2:error] [pid 15429:tid 15429] [client 172.71.130.221:62426] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.redish.org"] [uri "/api/shared/config/.env"] [unique_id "aAf471AJCIj39Xo8xFHWIwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-16 05:47:48
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
thefoofighter
2025-04-11 04:09:26
(1 year ago)
[Fri Apr 11 04:09:23.731308 2025] [:error] [pid 2392510] [client 172.71.130.221:35764] [client 172.7 ...
show more
[Fri Apr 11 04:09:23.731308 2025] [:error] [pid 2392510] [client 172.71.130.221:35764] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cathalmcnally.com"] [uri "/.DS_Store"] [unique_id "Z_iV83772OBF5E3YuEuQ2QAAAA0"]
[Fri Apr 11 04:09:23.885051 2025] [:error] [pid 2392510] [client 172.71.130.221:35764] [client 172.71.130.221] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "O
...
show less
Bad Web Bot
Web App Attack