🇸🇪
shab
2026-09-04 10:48:21
(1 hour ago)
Suspicious VPN activity
Brute-Force
🇸🇪
OnTheEdge
2026-09-04 05:23:18
(6 hours ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇺🇸
fbarela
2026-08-24 02:00:28
(1 week ago)
FortiGate SSL VPN login failures.
Brute-Force
Hacking
🇩🇪
LRob
2026-07-02 00:02:44
(2 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
🇩🇪
4server
2026-06-06 18:32:46
(2 months ago)
[SatJun0620:32:44.1699362026][security2:error][pid2663872:tid2664011][client209.50.167.64:0]ModSecur ...
show more
[SatJun0620:32:44.1699362026][security2:error][pid2663872:tid2664011][client209.50.167.64:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"prstartup.ch\"][uri\"/wp-json/gravitysmtp/v1/tests/mock-data\"][unique_id\"aiRnzNk0TztosfxjxUmj3gAAAQE\"]
show less
Port Scan
Brute-Force
Web App Attack
🇪🇸
librebit
2026-05-17 05:24:32
(3 months ago)
Brute force
Brute-Force
🇺🇸
TPI-Abuse
2025-12-27 22:32:50
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 17:32:45.986818 2025] [security2:error] [pid 606598:tid 606624] [client 209.50.167.64:35033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darrylrichards.com"] [uri "/.git/HEAD"] [unique_id "aVBejQt3y9Uh9Fw1HlB-EQAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-27 21:55:43
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 16:55:37.804088 2025] [security2:error] [pid 20762:tid 20762] [client 209.50.167.64:45365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evelowerealtor.com"] [uri "/.svn/wc.db"] [unique_id "aVBV2czbvCPYBIGlR5fl6wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-27 21:04:11
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 16:04:08.265890 2025] [security2:error] [pid 16413:tid 16413] [client 209.50.167.64:21039] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.trafficstopper.com"] [uri "/.git/HEAD"] [unique_id "aVBJyF0l3jhrjZY3O0O-uQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-27 20:08:02
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.167.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 15:07:54.479842 2025] [security2:error] [pid 4920:tid 4920] [client 209.50.167.64:27289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dianadelapava.com"] [uri "/.env"] [unique_id "aVA8mm3CIz5LiVCoDvpvvwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2025-12-27 04:30:03
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2025-12-26 15:51:06
(8 months ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
🇫🇷
mrcrassi
2025-12-25 02:49:25
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇮🇹
VHosting
2025-12-23 18:55:15
(8 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
🇫🇷
mrcrassi
2025-12-16 00:12:41
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot