๐ฌ๐ง
consul.to
2026-06-04 14:51:13
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-06-04 13:05:32
(2 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-05-05 22:34:48
(1 month ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-04 22:28:37
(1 month ago)
Brute-Force
Web App Attack
๐ซ๐ฎ
Rexikon
2026-05-04 15:39:47
(1 month ago)
188.212.135.180 - - [04/May/2026:17:39:46 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://pa ...
show more
188.212.135.180 - - [04/May/2026:17:39:46 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.180 - - [04/May/2026:17:39:46 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/140.0.3124.85"
188.212.135.180 - - [04/May/2026:17:39:46 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.180 - - [04/May/2026:17:39:46 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.180 - - [04/May/2026:17:39:47 +
...
show less
Brute-Force
๐บ๐ธ
mnsf
2026-05-04 15:05:25
(1 month ago)
Login Too Frequent (8)
Brute-Force
Web App Attack
๐ซ๐ฎ
Rexikon
2026-05-04 12:47:17
(1 month ago)
188.212.135.180 - - [04/May/2026:14:47:15 +0200] "POST /wp-login.php HTTP/1.0" 200 14548 "https://fa ...
show more
188.212.135.180 - - [04/May/2026:14:47:15 +0200] "POST /wp-login.php HTTP/1.0" 200 14548 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
188.212.135.180 - - [04/May/2026:14:47:15 +0200] "POST /wp-login.php HTTP/1.0" 200 14548 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.3124.85"
188.212.135.180 - - [04/May/2026:14:47:15 +0200] "POST /wp-login.php HTTP/1.0" 200 14532 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.180 - - [04/May/2026:14:47:16 +0200] "POST /wp-login.php HTTP/1.0" 200 14548 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36"
188.212.135.180 - - [04/May/2026:14:47:16 +0200] "POST /wp-login.php HTTP/1
...
show less
Brute-Force
๐ซ๐ฎ
Rexikon
2026-05-04 12:28:16
(1 month ago)
188.212.135.180 - - [04/May/2026:14:28:14 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://fa ...
show more
188.212.135.180 - - [04/May/2026:14:28:14 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
188.212.135.180 - - [04/May/2026:14:28:14 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.180 - - [04/May/2026:14:28:14 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.180 - - [04/May/2026:14:28:14 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.180 - - [04/May/2026:14:28:15 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://f
...
show less
Brute-Force
๐ง๐ช
cmbplf
2026-05-03 08:00:27
(1 month ago)
5.093 4xx requests in 1 hour (1w2d9h)
Brute-Force
Bad Web Bot
๐ซ๐ฎ
as211431.net
2026-05-03 06:23:39
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /about.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-04-28 10:04:10
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐จ๐ณ
pengpeng
2026-04-27 12:21:02
(1 month ago)
monitor: on VM-0-7-ubuntu | port: 15818 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporte ...
show more
monitor: on VM-0-7-ubuntu | port: 15818 | ttl: 251 script: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฌ๐ง
consul.to
2026-04-26 09:16:59
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 07:15:48
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 188.212.135.180 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 188.212.135.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 03:15:41.544757 2026] [security2:error] [pid 25702:tid 25702] [client 188.212.135.180:27233] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||phantomquailkennel.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phantomquailkennel.com"] [uri "/backups/wallet.dat"] [unique_id "acDonQn7-xiNvxX9CVESwgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 17:44:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 188.212.135.180 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 188.212.135.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 12:44:04.013551 2026] [security2:error] [pid 31070:tid 31070] [client 188.212.135.180:37221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qualityelevatorcabs.com"] [uri "/bak/sftp-config.json"] [unique_id "aaXMZChiD8dvV-Mr_3ms_wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack