๐ฉ๐ช
palla89
2026-06-27 00:02:53
(7 hours ago)
(wordpress) Failed wordpress login from 172.71.172.6 (DE/Germany/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-26 12:57:34
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 08:57:30.392318 2026] [security2:error] [pid 18412:tid 18412] [client 172.71.172.6:12686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.labelrecord.com"] [uri "/.git/config"] [unique_id "aj53OrZdHi32Gn8d_So1QwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
palla89
2026-06-25 09:54:33
(1 day ago)
(wordpress) Failed wordpress login from 172.71.172.6 (DE/Germany/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-24 23:58:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 19:58:18.216273 2026] [security2:error] [pid 15435:tid 15435] [client 172.71.172.6:12077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabecocont.com"] [uri "/.env.bak"] [unique_id "ajxvGoXyDlasQnQLUMJbjAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 17:38:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 13:38:42.483195 2026] [security2:error] [pid 1153:tid 1241] [client 172.71.172.6:11509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prominentregroup.com"] [uri "/.env.development.local"] [unique_id "ajwWIm0IlBVWiZrRCQa3fwAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 05:43:47
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 01:43:37.767419 2026] [security2:error] [pid 32339:tid 32346] [client 172.71.172.6:11108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.extrememakeovers.us.aafm.us"] [uri "/.git/config"] [unique_id "ajd6CcXVjVz-IpbFLCUpggAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 08:34:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 04:34:41.612734 2026] [security2:error] [pid 16232:tid 16232] [client 172.71.172.6:11603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petrovic4.com"] [uri "/.git/config"] [unique_id "ajEKoZoyUiMopHrkNPz6ewAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-06-13 18:12:25
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /telescope/requests
UA: Mozilla/5.0 (l9scan/2.0.8393e26323e28313e2430313; +https://leakix.net)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-06-10 11:05:28
(2 weeks ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-admin/install.php
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-04 06:16:21
(3 weeks ago)
Try to access /.git/config
Web App Attack
Anonymous
2026-06-03 04:48:01
(3 weeks ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-02 15:33:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 11:33:21.028675 2026] [security2:error] [pid 9508:tid 9508] [client 172.71.172.6:10758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nickmontfort.com"] [uri "/.git/config"] [unique_id "ah73weobLWz7XMpog5IO6gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:12:58
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:12:54.552254 2026] [security2:error] [pid 8347:tid 8347] [client 172.71.172.6:11777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maryrosevaro.com"] [uri "/.git/config"] [unique_id "ah7k5oHNe5OKfz_qMogCjQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 13:41:46
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.172.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 09:41:39.328011 2026] [security2:error] [pid 7280:tid 7366] [client 172.71.172.6:9887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.isignsdk.com"] [uri "/.git/config"] [unique_id "ahhGE2JVP3f-ixCURFUd-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
psauxit
2026-05-21 17:20:45
(1 month ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking