๐ฌ๐ง
consul.to
2026-06-04 14:51:08
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-05 22:34:43
(3 months ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-04 22:28:31
(3 months ago)
Brute-Force
Web App Attack
๐ซ๐ฎ
Rexikon
2026-05-04 17:50:00
(3 months ago)
188.212.135.165 - - [04/May/2026:19:49:56 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://an ...
show more
188.212.135.165 - - [04/May/2026:19:49:56 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
188.212.135.165 - - [04/May/2026:19:49:57 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.165 - - [04/May/2026:19:49:58 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
188.212.135.165 - - [04/May/2026:19:49:58 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
188.212.135.165 - - [04/May/2026:19:49:59 +0200] "POST /wp-login.php HT
...
show less
Brute-Force
๐ซ๐ฎ
Rexikon
2026-05-04 16:06:23
(3 months ago)
188.212.135.165 - - [04/May/2026:18:06:22 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://pa ...
show more
188.212.135.165 - - [04/May/2026:18:06:22 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.165 - - [04/May/2026:18:06:22 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
188.212.135.165 - - [04/May/2026:18:06:22 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.165 - - [04/May/2026:18:06:22 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 OPR/120.0.0.0"
188.212.135.165 - - [04/May/2026:18:06:23 +0200]
...
show less
Brute-Force
๐บ๐ธ
mnsf
2026-05-04 15:05:37
(3 months ago)
Login Too Frequent (8)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-05-04 04:27:44
(3 months ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-03 06:24:04
(3 months ago)
Triggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-content/themes/classwithtostring.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-04-28 10:04:04
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-28 07:48:26
(3 months ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ง
consul.to
2026-04-26 09:16:49
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
Alvino
2026-04-04 13:02:25
(4 months ago)
Blocked due to using a VPN or data center IP with abuse: 19
Web Spam
VPN IP
๐บ๐ธ
TPI-Abuse
2026-03-23 06:36:14
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 188.212.135.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 188.212.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 02:36:06.197150 2026] [security2:error] [pid 9066:tid 9066] [client 188.212.135.165:51255] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||qualityelevatorcabs.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "qualityelevatorcabs.com"] [uri "/back/dump.sql"] [unique_id "acDfVoyd08IDtHed2Iw0_AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 23:19:23
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 188.212.135.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 188.212.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 19:19:18.290421 2026] [security2:error] [pid 2597:tid 2597] [client 188.212.135.165:52607] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usbea.com"] [uri "/bak/sftp-config.json"] [unique_id "ab8ndqBMGAMRgGqXJLhnkAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 11:42:19
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 188.212.135.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 188.212.135.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 07:42:11.041813 2026] [security2:error] [pid 8192:tid 8192] [client 188.212.135.165:31443] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ilandman.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ilandman.com"] [uri "/sql.sql"] [unique_id "ab6EE84hf3eILBQ7HVnmnQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack