๐ฌ๐ง
consul.to
2026-09-25 13:33:44
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
www.tana.it
2026-09-24 22:52:23
(22 hours ago)
PHP scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:16:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:16:41.948614 2026] [security2:error] [pid 23991:tid 23991] [client 178.62.0.161:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "package.cloudex.click"] [uri "/.env"] [unique_id "arTqeahY4METxYoSnBmY8AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-24 06:25:02
(1 day ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:19:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:19:23.794732 2026] [security2:error] [pid 2744:tid 2744] [client 178.62.0.161:58654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "souldata.com"] [uri "/wp-config.php.bak"] [unique_id "arTA64gBpA-y_lkFDWN08AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-24 05:01:12
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:38:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:38:29.017587 2026] [security2:error] [pid 9911:tid 9911] [client 178.62.0.161:40072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elcocosportfishing.com"] [uri "/wp-config.php.bak"] [unique_id "arK9FWH6kNrEOudVTPVqigAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 02:55:02
(3 days ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 00:29:16
(3 days ago)
108 requests with url.path */debug.log
105 requests with url.path *debug.log
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-22 00:01:35
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:43:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.0.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:43:33.625370 2026] [security2:error] [pid 15791:tid 15791] [client 178.62.0.161:40096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "femalegamblers.org"] [uri "/wp-config.php.bak"] [unique_id "arHBJZjNQAE0P9VnsoVh6wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-21 22:56:03
(3 days ago)
Bad behaviour
Web Spam
๐ซ๐ฎ
as211431.net
2026-09-20 07:57:14
(5 days ago)
Triggered Cloudflare WAF (linkMaze) from GB.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from GB.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-19 12:40:53
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
SX Communications
2026-09-19 08:39:13
(6 days ago)
Blocked abusive HTTP application-layer DoS / botnet traffic from 178.62.0.161: traffic from this add ...
show more
Blocked abusive HTTP application-layer DoS / botnet traffic from 178.62.0.161: traffic from this address continues high-cost dynamic page and feed requests at abusive rates via TCP/HTTPS despite edge block responses. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host