๐ฉ๐ช
neckaralb-admin.de
2026-09-22 05:55:47
(2 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
xmission.com
2026-09-16 08:26:35
(2 weeks ago)
Blocked by UFW (TCP on 51413)
Source port: 33995
TTL: 115
Packet length: 52
TOS: 0x08
This report ( ...
show more
Blocked by UFW (TCP on 51413)
Source port: 33995
TTL: 115
Packet length: 52
TOS: 0x08
This report (for 185.251.19.154) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-11 02:22:50
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:22:16.104995 2026] [security2:error] [pid 338:tid 338] [client 185.251.19.154:57179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.61"] [uri "/wp-content/.env"] [unique_id "aqNl2PThMh2P0UA_dwpbRgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 01:59:57
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:949110) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:59:48.494737 2026] [security2:error] [pid 301:tid 301] [client 185.251.19.154:23557] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/laravel/.env"] [unique_id "aqNglEYEY3IhpxbHZ7znMAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 23:15:32
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:15:03.807199 2026] [security2:error] [pid 31798:tid 31798] [client 185.251.19.154:34979] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.189"] [uri "/www/.env"] [unique_id "aqM59wQyFMEVjcZRWHDEvAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 19:50:22
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 15:49:49.619286 2026] [security2:error] [pid 15688:tid 15688] [client 185.251.19.154:48651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.89"] [uri "/local/.env"] [unique_id "aqMJ3XhfHZ-sXolW2gyR1QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-19 15:45:02
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-16 15:46:00
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐น๐ท
neron
2026-08-15 23:06:48
(1 month ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-08-15 11:19:33
(1 month ago)
Hacking Attempt (Website Honeypot)
Hacking
Web App Attack
๐ฉ๐ช
gadix
2026-08-14 15:42:20
(1 month ago)
185.251.19.154 - - [14/Aug/2026:17:32:15 +0200] "POST /wp-login.php HTTP/1.1" 200 16606 "-" "Mozilla ...
show more
185.251.19.154 - - [14/Aug/2026:17:32:15 +0200] "POST /wp-login.php HTTP/1.1" 200 16606 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
185.251.19.154 - - [14/Aug/2026:17:41:08 +0200] "POST /wp-login.php HTTP/1.1" 200 16601 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0"
185.251.19.154 - - [14/Aug/2026:17:42:17 +0200] "POST /wp-login.php HTTP/1.1" 200 3317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/
...
show less
Web App Attack
๐ซ๐ท
mrcrassi
2026-08-12 15:29:06
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; rv:143.0) Gecko/20100101 Firefox/143.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Equity Steward
2026-08-12 15:15:24
(1 month ago)
Systematic automated scraping and endpoint enumeration against equitysteward.org. 1 offences recorde ...
show more
Systematic automated scraping and endpoint enumeration against equitysteward.org. 1 offences recorded. Trigger: Honeypot path accessed: /wp-login.php โ deliberately ignored robots.txt Disallow directive.. Canary ref: ab2b464a-f61.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-11 14:12:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 10:11:49.709777 2026] [security2:error] [pid 3819914:tid 3819914] [client 185.251.19.154:36953] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.100"] [uri "/app/config/.env"] [unique_id "anstpbkEQCsiqXz4--l1rwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 13:49:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.154 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 09:48:25.360860 2026] [security2:error] [pid 3493592:tid 3493592] [client 185.251.19.154:60213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.55"] [uri "/library/.env"] [unique_id "ansoKW-6ovG-ILZZs4vcaQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack