๐ฆ๐บ
MAGIC
2025-12-29 02:08:27
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ซ๐ฎ
as211431.net
2025-12-24 19:54:37
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /old//kickstart.php
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.3814.1083 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐น
VHosting
2025-12-23 15:45:29
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
myagent.site
2025-12-12 17:14:21
(6 months ago)
Blocking for trying to access an exploit file: /old//kickstart.php
Hacking
๐บ๐ธ
TPI-Abuse
2025-11-26 08:47:01
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:46:54.499772 2025] [security2:error] [pid 30897:tid 30897] [client 193.56.28.204:9427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gpaarch.com"] [uri "/.git/HEAD"] [unique_id "aSa-fq8UWrcVZKO99017lQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:54:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:54:42.024237 2025] [security2:error] [pid 28326:tid 28326] [client 193.56.28.204:60743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kulacenterky.com"] [uri "/.svn/wc.db"] [unique_id "aSZP0m2D8kYYMDT3t9t6JwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:42:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:42:31.460685 2025] [security2:error] [pid 5228:tid 5228] [client 193.56.28.204:59065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.northcoastgolfden.com"] [uri "/.svn/wc.db"] [unique_id "aSP-V-G_cD0JTsk35HQB6wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 02:02:00
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 08:04:46
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 03:04:42.022768 2025] [security2:error] [pid 30434:tid 30434] [client 193.56.28.204:56413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.commonthreadsvt.org"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aRLuGlTJEkWCnlkAUkhEMQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-02 16:37:36
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 07:09:43
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐น
Rosh
2025-10-18 19:21:17
(8 months ago)
[10/18/25 21:21:17] SSH: illegal login attempts
Brute-Force
SSH
Anonymous
2025-10-15 17:30:42
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-14 00:14:08
(8 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force
๐ฌ๐ง
D3monite
2025-10-10 08:56:17
(8 months ago)
Attempted Brute Force (cpaneld)
Brute-Force
Anonymous
2025-10-05 12:54:51
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.05 is noted in report timestamp
show less
Hacking
Brute-Force