๐บ๐ธ
Penny Packer
2026-05-05 16:04:56
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฎ๐ณ
evicky2002
2026-05-05 06:00:00
(4 months ago)
Confirmed malicious by STILWaters CTI platform (score=86, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-05-04 09:20:58
(4 months ago)
FortiWeb WAF: 32 attacks detected. Threat Score: 17800. Types: Client Management(16), Block IP List( ...
show more
FortiWeb WAF: 32 attacks detected. Threat Score: 17800. Types: Client Management(16), Block IP List(16). Origin: Switzerland.
show less
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-03 22:36:22
(4 months ago)
Brute-Force
Web App Attack
๐ซ๐ฎ
as211431.net
2026-05-03 08:45:31
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from CH.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CH.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: //vendor/phpunit/phpunit/phpunit.xsd
UA: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
dtorrer
2026-05-03 07:15:45
(4 months ago)
General vulnerability scan.
Port Scan
Anonymous
2026-05-03 06:07:03
(4 months ago)
Fail2Ban triggered
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 03:19:57
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 23:19:50.744566 2026] [security2:error] [pid 10012:tid 10012] [client 20.250.147.244:61863] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||al-hafeeztrust.net|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "al-hafeeztrust.net"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "afa-1utqxXzB_jm8mIfHBwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-05-03 02:58:43
(4 months ago)
3.169 requests from abuseipdb.com blacklisted IP (9mos2w3h)
Brute-Force
Bad Web Bot
๐ฆ๐บ
Anytech
2026-05-03 00:38:37
(4 months ago)
Blocked by Conn-Monitor: Web scanning activity
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-02 22:19:08
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 18:19:02.095322 2026] [security2:error] [pid 28900:tid 28961] [client 20.250.147.244:59529] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lbakkercpa.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lbakkercpa.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "afZ4VonenxWn6giLLBPJ6QAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-02 18:45:39
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 14:45:33.919660 2026] [security2:error] [pid 3166:tid 3181] [client 20.250.147.244:54384] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mykfccares.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mykfccares.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "afZGTceOcIl8Vm8hHfE_kwAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-05-02 16:54:04
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (CH/Switzerland/-): 5 in the las ...
show more
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (CH/Switzerland/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
Anonymous
2026-05-02 15:04:14
(4 months ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CH, Attack patterns: Auto ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CH, Attack patterns: Automated scanning
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-02 11:23:55
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 20.250.147.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 02 07:23:48.458307 2026] [security2:error] [pid 10416:tid 10416] [client 20.250.147.244:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vertubet.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vertubet.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "afXexHgxHONiPm3D8OjB-AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack