Anonymous
2026-07-25 03:07:02
(24 minutes ago)
Automated web scanner. Requested suspicious paths: /vendor/phpunit/phpunit/phpunit.xsd. UTC: 2026-07 ...
show more
Automated web scanner. Requested suspicious paths: /vendor/phpunit/phpunit/phpunit.xsd. UTC: 2026-07-25 02:30:30.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 02:49:15
(41 minutes ago)
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:49:07.401840 2026] [security2:error] [pid 1618205:tid 1618205] [client 20.215.232.116:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nyemdr.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nyemdr.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amQkIyOGOCtqFfdB_Snl_QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
blinx
2026-07-25 00:24:23
(3 hours ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
πΊπΈ
its101
2026-07-25 00:15:05
(3 hours ago)
Automated detection by LockdownAccess security system. Attack type(s): rce. Reason: Nginx: rce attac ...
show more
Automated detection by LockdownAccess security system. Attack type(s): rce. Reason: Nginx: rce attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 21:25:58
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 17:25:53.077467 2026] [security2:error] [pid 1376771:tid 1376771] [client 20.215.232.116:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||colonybet.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "colonybet.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amPYYQIaafF7cIPkFHnZgQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-07-24 21:15:32
(6 hours ago)
(PERMBLOCK) 20.215.232.116 (PL/Poland/-) has had more than 4 temp blocks in the last 86400 secs; Por ...
show more
(PERMBLOCK) 20.215.232.116 (PL/Poland/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
Anonymous
2026-07-24 20:17:04
(7 hours ago)
Automatically blocked after 1 security event. Observed PHPUnit exploit probes. Source: Cloudflare se ...
show more
Automatically blocked after 1 security event. Observed PHPUnit exploit probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
π¬π§
pinguin
2026-07-24 20:09:51
(7 hours ago)
Triggered Cloudflare WAF (firewallManaged) from PL.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from PL.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: //vendor/phpunit/phpunit/phpunit.xsd
UA: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π©πͺ
kkwemi
2026-07-24 15:28:07
(12 hours ago)
Blocked by block-exploit-paths on /vendor/phpunit/phpunit/phpunit.xsd
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-24 14:58:57
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:58:53.493310 2026] [security2:error] [pid 5168:tid 5168] [client 20.215.232.116:58641] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.floridausa.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.floridausa.com"] [uri "/wmia/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amN9rVdqnXG9NLZVYa5RkgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
ELYAZ
2026-07-24 14:40:36
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 20.215.232.116 (PL/Poland/-): (CF_ENAB ...
show more
(mod_security) mod_security triggered on hostname [redacted] 20.215.232.116 (PL/Poland/-): (CF_ENABLE)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-07-24 14:01:56
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.215.232.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:01:49.291773 2026] [security2:error] [pid 4119603:tid 4119603] [client 20.215.232.116:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uwsvita.org|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uwsvita.org"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "amNwTY_xc7tHCTQ9oJqxVQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-07-24 12:50:39
(14 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.215.232.116 (PL/Poland/-): 1 in the l ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.215.232.116 (PL/Poland/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.215.232.116 - - [24/Jul/2026:14:50:36 +0200] "GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" "20.215.232.116" host=notaiopanella.it
show less
Port Scan
π©πͺ
maxpower
2026-07-24 12:07:30
(15 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.215.232.116 (PL/Poland/-): 1 in the l ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 20.215.232.116 (PL/Poland/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 20.215.232.116 - - [24/Jul/2026:14:07:24 +0200] "GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" "20.215.232.116" host=direnzoassicurazioni.it
show less
Port Scan
π©πͺ
sverson
2026-07-24 11:47:20
(15 hours ago)
Wordpress Attack Attempt
Web App Attack