Anonymous
2026-02-20 07:04:52
(3 months ago)
GlobalProtect Password Spraying
Brute-Force
๐ต๐ฑ
sefinek.net
2026-01-22 15:08:17
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-12-24 00:02:58
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-09 16:04:04
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 185.77.220.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.77.220.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 11:03:57.587623 2025] [security2:error] [pid 15754:tid 15754] [client 185.77.220.37:37511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||andrsn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "andrsn.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aThIbTcQzxKgi4Xwfd285wAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-10 14:25:03
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ซ๐ท
tecnicorioja
2025-11-04 23:01:27
(7 months ago)
wp-login attack [04/Nov/2025:04:08:50
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-31 15:25:43
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 185.77.220.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 185.77.220.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 31 11:25:37.201609 2025] [security2:error] [pid 12243:tid 12243] [client 185.77.220.37:19345] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.whitetailridgeantiques.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.whitetailridgeantiques.com"] [uri "/"] [unique_id "aQTU8ZvB72OoXtuk2JI-tQAAAAA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-14 12:59:02
(1 year ago)
Brute force attempt to access portal using various usernames
Brute-Force
๐บ๐ธ
Bryan Lemas
2024-10-08 16:34:48
(1 year ago)
"Attempts to brute force our VPN"
Brute-Force
๐ต๐ฑ
sefinek.net
2024-08-30 12:01:11
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPad; CPU OS 12_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.1 Mobile/16C50 Safari/604.1 - -
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2024-08-30 12:01:11
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPad; CPU OS 12_1_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.1 Mobile/16C50 Safari/604.1 - -
show less
Bad Web Bot
๐ฌ๐ง
essinghigh
2024-04-30 20:27:15
(2 years ago)
1714508835 # Service_probe # SIGNATURE_SEND # source_ip:185.77.220.37 # dst_port:5607
...
Port Scan
๐จ๐ฆ
Justmee
2023-09-29 22:49:42
(2 years ago)
Sep 29 16:49:38 server1 kernel: [1069489.755587] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42: ...
show more
Sep 29 16:49:38 server1 kernel: [1069489.755587] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=185.77.220.37 DST=192.168.100.3 LEN=52 TOS=0x00 PREC=0x00 TTL=120 ID=61915 DF PROTO=TCP SPT=65297 DPT=443 WINDOW=42340 RES=0x00 SYN URGP=0
Sep 29 16:49:39 server1 kernel: [1069490.776187] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=185.77.220.37 DST=192.168.100.3 LEN=52 TOS=0x00 PREC=0x00 TTL=120 ID=61916 DF PROTO=TCP SPT=65297 DPT=443 WINDOW=42340 RES=0x00 SYN URGP=0
Sep 29 16:49:41 server1 kernel: [1069492.792422] IPTABLES: IN=eth0 OUT= MAC=00:22:19:d7:2c:94:04:42:1a:61:50:d8:08:00 SRC=185.77.220.37 DST=192.168.100.3 LEN=52 TOS=0x00 PREC=0x00 TTL=120 ID=61917 DF PROTO=TCP SPT=65297 DPT=443 WINDOW=42340 RES=0x00 SYN URGP=0
...
show less
Hacking
Brute-Force
๐จ๐ฆ
mitsurugi
2023-09-10 18:47:42
(2 years ago)
Drupal brute-force attack.
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2023-05-02 11:59:38
(3 years ago)
honeypot
Bad Web Bot