Anonymous
2026-10-04 22:48:34
(16 hours ago)
fail2ban: apache-php-scan jail (1 hits in 2419200s) on skipper
Web App Attack
Hacking
Anonymous
2026-08-28 23:18:37
(1 month ago)
Global Protect brute force attempt
Brute-Force
Web App Attack
Anonymous
2026-08-26 13:18:15
(1 month ago)
GlobalProtect password spraying attempt.
Brute-Force
Web App Attack
Anonymous
2026-08-20 19:37:47
(1 month ago)
VPN portal credential brute-force / password spray against a SAML-only GlobalProtect portal (19 atte ...
show more
VPN portal credential brute-force / password spray against a SAML-only GlobalProtect portal (19 attempt(s) observed, 19 username(s) tried). Source blocked on our perimeter.
show less
Brute-Force
Anonymous
2026-08-20 06:38:07
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2026-08-20 06:24:05
(1 month ago)
Global protect password spraying
Brute-Force
Web App Attack
๐จ๐ฆ
DRI
2026-07-18 17:20:02
(2 months ago)
Web attack/Malicious activity detected
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-04-16 00:31:58
(5 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -53.221 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -53.221 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.2822.1
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
mrcrassi
2026-04-02 02:24:51
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: curl/8.6.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-26 04:33:50
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 193.163.207.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.163.207.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 23:33:44.764234 2026] [security2:error] [pid 22796:tid 22796] [client 193.163.207.56:42347] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||awcadvocate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "awcadvocate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZ_NKCkzkKLqGBFXC4fUPgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 19:16:56
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 193.163.207.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.163.207.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 14:16:50.619154 2026] [security2:error] [pid 1486:tid 1501] [client 193.163.207.56:21011] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||41bravo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "41bravo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aZtWIv1AFRAa00789rb5iQAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-02-08 03:36:28
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 193.163.207.56 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 193.163.207.56 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-05 01:14:01
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 193.163.207.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 193.163.207.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 04 20:13:54.022358 2026] [security2:error] [pid 369781:tid 369781] [client 193.163.207.56:58069] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aYPu0ptrWP8Qro63xZqehwAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-02-04 03:05:04
(8 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ซ๐ท
polido
2026-01-30 01:46:59
(8 months ago)
Unauthorized connection attempt to port 443 from 193.163.207.56
Port Scan