๐บ๐ธ
TAY
2026-06-12 15:38:10
(2 days ago)
209.50.161.160 - - [12/Jun/2026:23:37:04 +0800] "POST /wp-login.php HTTP/1.1" 200 6914 "https://batu ...
show more
209.50.161.160 - - [12/Jun/2026:23:37:04 +0800] "POST /wp-login.php HTTP/1.1" 200 6914 "https://batukerascafe.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:120.0) Gecko/20100101 Firefox/120.0"
209.50.161.160 - - [12/Jun/2026:23:37:26 +0800] "POST /wp-login.php HTTP/1.1" 200 6914 "https://batukerascafe.com/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
209.50.161.160 - - [12/Jun/2026:23:38:04 +0800] "POST /wp-login.php HTTP/1.1" 200 6914 "https://batukerascafe.com/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ซ๐ท
ELYAZ
2026-06-09 18:09:17
(5 days ago)
(y4) Failed scan -byebye- from 209.50.161.160 (US/United States/-): (CF_ENABLE)
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-20 09:07:07
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 04:06:59.846957 2026] [security2:error] [pid 29883:tid 29883] [client 209.50.161.160:52219] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cobbwebb.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cobbwebb.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZgkM3sAyEHeMzYl47rvBQAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-19 03:42:12
(3 months ago)
Blocking for trying to access an exploit file: /.env.staging
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-18 18:30:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:30:40.862632 2026] [security2:error] [pid 8414:tid 8414] [client 209.50.161.160:19523] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevillageartcenter.com"] [uri "/dev/.git/config"] [unique_id "aZYFUJON6G_uyKl1v4_1JwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-02-18 13:31:33
(3 months ago)
http-sensitive-files - IP: 209.50.161.160 - time="2026-02-18T14:31:33+01:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 209.50.161.160 - time="2026-02-18T14:31:33+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 209.50.161.160 (US/200373) : 4h ban on Ip 209.50.161.160" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 13:20:35
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:20:27.749313 2026] [security2:error] [pid 4095394:tid 4095394] [client 209.50.161.160:30567] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willowgrovemusic.com"] [uri "/admin/.env"] [unique_id "aZW8m4HdDtziDsqhNSnuDgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 12:40:13
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 07:40:08.820408 2026] [security2:error] [pid 804532:tid 804541] [client 209.50.161.160:49119] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wehcad.com"] [uri "/app/.git/config"] [unique_id "aZWzKCVMIGSGO_bGgZBJswAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:48:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.161.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:48:24.491986 2026] [security2:error] [pid 4257:tid 4257] [client 209.50.161.160:21423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wandcompany.com"] [uri "/api/.git/config"] [unique_id "aZWnCOqRiaNlbNxbpxa9HgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-30 13:09:59
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
Anonymous
2025-10-29 05:40:27
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐ซ๐ท
mrcrassi
2025-10-18 10:34:44
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-10-17 18:53:38
(7 months ago)
Failed Wordpress login
Hacking
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-16 22:01:16
(7 months ago)
GlobalProtect login attempts with user vhoyos.
VPN IP
Brute-Force
Anonymous
2025-10-14 08:13:24
(8 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force