๐ง๐ฌ
Stoyko Stoykov
2026-07-22 14:28:12
(2 hours ago)
172.71.99.225 - - [22/Jul/2026:17:28:11 +0300] "GET /.env.production HTTP/1.1" 301 162 "-" "Mozilla/ ...
show more
172.71.99.225 - - [22/Jul/2026:17:28:11 +0300] "GET /.env.production HTTP/1.1" 301 162 "-" "Mozilla/4.77 [en] (X11; I; IRIX;64 6.5 IP30)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 23:18:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 19:18:12.039763 2026] [security2:error] [pid 13816:tid 13816] [client 172.71.99.225:11776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "runnercomics.com"] [uri "/.env.test"] [unique_id "ajxltLn94kDZ122TOfFtgAAAAB4"], referer: https://www.google.com/search?q=runnercomics.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 20:22:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 16:21:59.911128 2026] [security2:error] [pid 19598:tid 19598] [client 172.71.99.225:13499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thecrimsonpirate.com"] [uri "/.env.backup"] [unique_id "agTdZ6u0NaZMUYtvgwGFzwAAAAI"], referer: https://www.google.com/search?q=webdisk.thecrimsonpirate.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Campus France
2026-01-24 03:34:53
(5 months ago)
[Sat Jan 24 04:34:36.003054 2026] [php:error] [pid 2507477] [client 172.71.99.225:13417] script '/va ...
show more
[Sat Jan 24 04:34:36.003054 2026] [php:error] [pid 2507477] [client 172.71.99.225:13417] script '/var/www/html/file2.php' not found or unable to stat
[Sat Jan 24 04:34:49.236954 2026] [php:error] [pid 2508392] [client 172.71.99.225:13072] script '/var/www/html/xx.php' not found or unable to stat
[Sat Jan 24 04:34:51.579292 2026] [php:error] [pid 2508392] [client 172.71.99.225:13072] script '/var/www/html/moon.php' not found or unable to stat
[Sat Jan 24 04:34:52.231208 2026] [php:error] [pid 2508392] [client 172.71.99.225:13072] script '/var/www/html/file21.php' not found or unable to stat
[Sat Jan 24 04:34:52.555884 2026] [php:error] [pid 2508392] [client 172.71.99.225:13072] script '/var/www/html/xxw.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-01-21 05:06:55
(6 months ago)
[redacted] 172.71.99.225 - - [21/Jan/2026:06:06:53 +0100] "GET /.[redacted] HTTP/2.0" 301 200 "-" "M ...
show more
[redacted] 172.71.99.225 - - [21/Jan/2026:06:06:53 +0100] "GET /.[redacted] HTTP/2.0" 301 200 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0" [redacted] 172.71.99.225 - - [21/Jan/2026:06:06:54 +0100] "GET /fr/.[redacted]/ HTTP/2.0" 404 24886 "https://[redacted]/.[redacted]" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
juutis
2025-10-24 22:26:55
(8 months ago)
Multiple WAF abuses - IP blocked
Hacking
Brute-Force
Web App Attack
๐ฎ๐น
alph44
2025-10-14 04:51:48
(9 months ago)
WordPress attack detected by fail2ban: 3 failed attempts
Web App Attack
๐ซ๐ท
dynamix
2025-10-11 23:48:00
(9 months ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
pinguin
2025-09-22 11:17:27
(10 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Scrapy/2.12.0 (+https://scrapy.org)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
el-brujo
2025-09-01 13:39:43
(10 months ago)
01/Sep/2025:15:39:42.636176 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
01/Sep/2025:15:39:42.636176 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.99.225] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at REQUEST_COOKIES:g. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: echo found within REQUEST_COOKIES:g: echo Sp3ctra"] [severity "CRITICAL"] [ver "
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-14 12:14:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 14 08:14:46.335226 2025] [security2:error] [pid 2193520:tid 2193520] [client 172.71.99.225:36010] [client 172.71.99.225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ndanetworks.com"] [uri "/.git/config"] [unique_id "Z_z8NqvVvPs1YmbvVIYNjQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-07 05:46:03
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 07 01:45:55.819734 2025] [security2:error] [pid 7793:tid 7793] [client 172.71.99.225:18776] [client 172.71.99.225] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.43.76.198 (6+1 hits since last alert)|newmanwood.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "newmanwood.com"] [uri "/xmlrpc.php"] [unique_id "Z_NmkzFnReKB8rlWxT1jLgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-05 09:42:44
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 05 05:42:39.605805 2025] [security2:error] [pid 17187:tid 17187] [client 172.71.99.225:24008] [client 172.71.99.225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.179vfs.com"] [uri "/.env"] [unique_id "Z_D7Dwp5TWCGGvDMgz3_cwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-25 21:43:02
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.99.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 25 16:42:56.788959 2025] [security2:error] [pid 27557:tid 27557] [client 172.71.99.225:41896] [client 172.71.99.225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "redish.org"] [uri "/.env"] [unique_id "Z745YHe5ZiePOE12W5w6uwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2025-02-19 04:40:57
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack