๐ฎ๐ฉ
David Koswari
2026-03-25 06:55:00
(5 months ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐จ๐ฆ
1gz
2026-03-21 20:35:39
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /uploads/1.php
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
N2N
2026-03-21 13:33:47
(5 months ago)
Hacking
Web App Attack
๐บ๐ธ
SiliSoftware
2026-03-20 10:27:10
(5 months ago)
/include/11.php
Web App Attack
๐ต๐น
Subnet Shadow Specter
2026-03-19 16:02:31
(5 months ago)
[Security Alert] Targeted exploit scanning against Textbook Vulnerabilities. Bot hunting for PHP bac ...
show more
[Security Alert] Targeted exploit scanning against Textbook Vulnerabilities. Bot hunting for PHP backdoors. [Method]: GET. [Request]: => /api/logins.php. Access revoked. [User-Agent]: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11. [OS]: Windows. [IP Address]: 182.96.164.18. [Date]: 2026-03-19 13:12:14 UTC.
show less
Bad Web Bot
Hacking
Web App Attack
๐ซ๐ท
IRISIO
2026-03-09 08:41:13
(6 months ago)
scans/SQL injection/spam posts : 4 queries
Web App Attack
SQL Injection
๐บ๐ธ
vdub144
2026-03-05 21:26:26
(6 months ago)
Automated report from Gross Automation security system. | Attack type: attack_path | Path: /public/1 ...
show more
Automated report from Gross Automation security system. | Attack type: attack_path | Path: /public/1234.php | UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11 | Blocked by: nginx-bot-hell
show less
Web App Attack
๐บ๐ธ
vdub144
2026-03-03 06:05:18
(6 months ago)
Automated report from Gross Automation security system. | Attack type: attack_path | Path: /tempp2.p ...
show more
Automated report from Gross Automation security system. | Attack type: attack_path | Path: /tempp2.php | UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.97 Safari/537.11 | Blocked by: nginx-bot-hell
show less
Web App Attack
๐บ๐ธ
myagent.site
2026-03-02 10:47:10
(6 months ago)
Blocking for trying to access an exploit file: /7.php
Hacking
๐บ๐ธ
nationaleventpros.com
2026-02-28 03:53:35
(6 months ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-11 06:28:04
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 182.96.164.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 182.96.164.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 11 01:27:59.002100 2026] [security2:error] [pid 23680:tid 23855] [client 182.96.164.18:55192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.castaspell.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.castaspell.com"] [uri "/base/install/index.php.bak"] [unique_id "aYwhbhYUFwsIi_R31s7qTQAAAVI"], referer: https://www.castaspell.com/base/install/index.php.bak
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-02-09 08:57:57
(7 months ago)
scans/SQL injection/spam posts : 1 queries
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-08 20:40:42
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 182.96.164.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 182.96.164.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 08 15:40:38.222179 2026] [security2:error] [pid 4711:tid 4711] [client 182.96.164.18:5062] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pakistanvision.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pakistanvision.com"] [uri "/base/install/index.php.bak"] [unique_id "aYj0xjRFiABGNV0b4d06GwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-02-08 04:00:04
(7 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-06 12:36:09
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 182.96.164.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 182.96.164.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 06 07:36:04.296222 2026] [security2:error] [pid 559493:tid 559493] [client 182.96.164.18:51311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dance4ovations.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dance4ovations.com"] [uri "/e/install/index.php.bak"] [unique_id "aYXgNDygUd2EvuZ2qiictwAAABA"], referer: https://www.dance4ovations.com/e/install/index.php.bak?enews=setdb&f=4
show less
Brute-Force
Bad Web Bot
Web App Attack