๐บ๐ธ
TPI-Abuse
2026-06-21 08:17:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 04:17:04.036728 2026] [security2:error] [pid 27813:tid 27813] [client 172.71.98.40:14048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.honeybeeawareness.com.garyrankin.com"] [uri "/.env.production"] [unique_id "ajeeAJzJdvPwOUlj430okQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐ฑ
router.al
2026-06-19 23:59:43
(3 days ago)
06/19/2026-23:59:42.132590 172.71.98.40 Protocol: 6 GPL WEB_SERVER 403 Forbidden
Port Scan
๐ท๐บ
DZBOT
2026-06-16 17:37:09
(1 week ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
Zydzy
2026-05-11 15:22:14
(1 month ago)
Automated attack detected. Server: 95.140.154.181. Jail: nginx-exploit.
Web App Attack
๐ฌ๐ง
pinguin
2025-09-11 02:12:18
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /dev/.env
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
sterile.network
2025-06-18 13:07:32
(1 year ago)
Blocked by UFW on ropanel1 [80/tcp]
Source port: 22982
TTL: 45
Packet length: 60
TOS: 0x08
Port Scan
Web App Attack
๐บ๐ธ
mawan
2025-06-07 04:50:41
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2025-05-26 17:15:08
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-22 14:48:41
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-05-08 16:07:00
(1 year ago)
2 port probes: tcp/8080 (http), tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-21 05:54:05
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 21 01:53:59.765701 2025] [security2:error] [pid 9606:tid 9606] [client 172.71.98.40:63552] [client 172.71.98.40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kryptonome.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kryptonome.com"] [uri "/backup/wallet.dat"] [unique_id "aAXdd-Ug1qz2UqLqh8Q1GQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-05 03:28:52
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 04 23:28:46.859123 2025] [security2:error] [pid 19855:tid 19855] [client 172.71.98.40:53536] [client 172.71.98.40] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.env"] [unique_id "Z_CjbjeAdkM07S8w_MGqLwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-03-30 13:00:37
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 14:04:52
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 10:04:49.342224 2025] [security2:error] [pid 30277:tid 30277] [client 172.71.98.40:39276] [client 172.71.98.40] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.365soft.top"] [uri "/.env"] [unique_id "Z9gsAV7hzG1qjomHtvWS1QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-14 04:04:08
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 172.71.98.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 14 00:04:01.922057 2025] [security2:error] [pid 3216453:tid 3216453] [client 172.71.98.40:14442] [client 172.71.98.40] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z9OqsWE9vdiKVv4san_EFAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack