๐ฉ๐ช
Ba-Yu
2026-06-04 22:51:53
(2 weeks ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-06-04 14:51:30
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-06-03 06:45:31
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-05 22:34:51
(1 month ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-04 22:28:39
(1 month ago)
Brute-Force
Web App Attack
๐ซ๐ฎ
Rexikon
2026-05-04 17:38:38
(1 month ago)
188.212.135.192 - - [04/May/2026:19:38:34 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://an ...
show more
188.212.135.192 - - [04/May/2026:19:38:34 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
188.212.135.192 - - [04/May/2026:19:38:35 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.192 - - [04/May/2026:19:38:35 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.192 - - [04/May/2026:19:38:36 +0200] "POST /wp-login.php HTTP/1.0" 200 14211 "https://anitra.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 OPR/120.0.0.0"
188.212.135.192 - - [04/May/2026:19:38:37 +0200] "POST /wp-log
...
show less
Brute-Force
๐ซ๐ฎ
Rexikon
2026-05-04 16:05:14
(1 month ago)
188.212.135.192 - - [04/May/2026:18:05:13 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://pa ...
show more
188.212.135.192 - - [04/May/2026:18:05:13 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/140.0.3124.85"
188.212.135.192 - - [04/May/2026:18:05:13 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.192 - - [04/May/2026:18:05:13 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.3124.85"
188.212.135.192 - - [04/May/2026:18:05:13 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
188.212.135.192 - -
...
show less
Brute-Force
๐ซ๐ฎ
Rexikon
2026-05-04 15:45:35
(1 month ago)
188.212.135.192 - - [04/May/2026:17:45:33 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://pa ...
show more
188.212.135.192 - - [04/May/2026:17:45:33 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/140.0.3124.85"
188.212.135.192 - - [04/May/2026:17:45:34 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.192 - - [04/May/2026:17:45:34 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.192 - - [04/May/2026:17:45:34 +0200] "POST /wp-login.php HTTP/1.0" 200 15967 "https://paramedic24.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 OPR/120.0.0.0"
188.212.135.192 - - [04/May/2
...
show less
Brute-Force
๐บ๐ธ
mnsf
2026-05-04 15:05:37
(1 month ago)
Login Too Frequent (8)
Brute-Force
Web App Attack
๐ซ๐ฎ
Rexikon
2026-05-04 12:39:05
(1 month ago)
188.212.135.192 - - [04/May/2026:14:39:03 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://fa ...
show more
188.212.135.192 - - [04/May/2026:14:39:03 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.192 - - [04/May/2026:14:39:03 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 OPR/120.0.0.0"
188.212.135.192 - - [04/May/2026:14:39:04 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/138.0"
188.212.135.192 - - [04/May/2026:14:39:04 +0200] "POST /wp-login.php HTTP/1.0" 200 14528 "https://faid.com.pl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
188.212.135.192 - - [04/May/2026:14:39:04 +0200] "POST /wp-login.
...
show less
Brute-Force
๐ซ๐ท
dynamix
2026-05-04 07:19:22
(1 month ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-03 06:25:52
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from PL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /uploads/
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-04-28 10:04:12
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-28 08:58:06
(1 month ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-18 12:54:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 188.212.135.192 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 188.212.135.192 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 08:54:51.478474 2026] [security2:error] [pid 20276:tid 20276] [client 188.212.135.192:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/back/sftp-config.json"] [unique_id "abqgm1ZGUrbIbpYQFCuESQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack