๐ฉ๐ช
pltcldvlpr
2026-09-18 17:14:13
(9 hours ago)
CMS/framework probe: 20.127.242.63 - - [18/Sep/2026:06:56:01 +0200] "GET /wp-json/gravitysmtp/v1/tes ...
show more
CMS/framework probe: 20.127.242.63 - - [18/Sep/2026:06:56:01 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 5131 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" asn=8075 org="Microsoft Corporation" country=US
...
show less
Web App Attack
Anonymous
2026-09-18 04:25:03
(22 hours ago)
[abuseipdb-autoban] 2026-09-18 04:25:02, Client: 20.127.242.63, Protocol: 6 (TCP), Service: HTTP, Ac ...
show more
[abuseipdb-autoban] 2026-09-18 04:25:02, Client: 20.127.242.63, Protocol: 6 (TCP), Service: HTTP, Activity: auto-banned after exceeding AbuseIPDB score threshold on visit to /, likely unclassified automated client, AbuseIPDB score at ban time: 86% (22 prior reports)
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-17 07:57:14
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐ซ๐ท
GoodOldTOS
2026-09-16 23:04:18
(2 days ago)
Highly suspect IP
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:00:14
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-14.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
Mehmet_The_Script_Kiddie
2026-09-15 21:12:18
(3 days ago)
CloudFlare WAF REPORT: Disobey robots.txt. Suspicious web crawler.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:55:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:55:02.931692 2026] [security2:error] [pid 25101:tid 25208] [client 20.127.242.63:54572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.writeonce.org"] [uri "/.env.backup"] [unique_id "aqkH5nbrI44585uJu8u9tgAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:17:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:17:07.798637 2026] [security2:error] [pid 8784:tid 8784] [client 20.127.242.63:40748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rainwaterconstruction.net"] [uri "/.git/index"] [unique_id "aqj_A6nuoVRQVY-9VY6kiQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:00:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:00:39.949544 2026] [security2:error] [pid 23665:tid 23665] [client 20.127.242.63:50926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nomorenicenice.net"] [uri "/.env.staging"] [unique_id "aqj7J2KhRzIBLCti-fPSgwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
1gz
2026-09-15 07:30:49
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฒ๐พ
Rizzy
2026-09-15 07:11:24
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 07:06:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:06:27.932903 2026] [security2:error] [pid 20456:tid 20456] [client 20.127.242.63:40426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.jazziiafoundation.org"] [uri "/.env.production"] [unique_id "aqjuc9o-p6F21V2ZSMaNVQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 06:21:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.127.242.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:21:25.283145 2026] [security2:error] [pid 24793:tid 24793] [client 20.127.242.63:44078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.carmichaellaw.org"] [uri "/.env.backup"] [unique_id "aqjj5W4OCc2RnQq2P320uAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-15 06:20:51
(3 days ago)
20.127.242.63 - - [15/Sep/2026:09:20:51 +0300] "GET /.env.txt HTTP/1.1" 400 63 "http://autodiscover. ...
show more
20.127.242.63 - - [15/Sep/2026:09:20:51 +0300] "GET /.env.txt HTTP/1.1" 400 63 "http://autodiscover.carmenhotel.ro/.env.txt" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
20.127.242.63 - - [15/Sep/2026:09:20:51 +0300] "GET /.git/config HTTP/1.1" 400 63 "http://autodiscover.carmenhotel.ro/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Web App Attack