๐ซ๐ท
mrcrassi
2026-07-22 02:17:40
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
PeravixGroup
2026-05-20 19:35:50
(2 months ago)
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran. ...
show more
Honeypot detection: FTP brute-force or anonymous access attempt on port 21. Severity: MEDIUM. Aaran.cloud
show less
FTP Brute-Force
Brute-Force
๐จ๐ญ
4server
2026-04-29 12:00:19
(2 months ago)
[WedApr2914:00:12.2427262026][security2:error][pid1367302:tid1368484][client209.50.176.90:0]ModSecur ...
show more
[WedApr2914:00:12.2427262026][security2:error][pid1367302:tid1368484][client209.50.176.90:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"4hosts.net\"][uri\"/\"][unique_id\"afHyzJfxTQ5wORC9PckBqgAAAQI\"]
show less
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-04-02 18:07:32
(3 months ago)
IM360 WAF: Possible SQL injection attack MV:ASC'))--
SQL Injection
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:58:58
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-02 19:11:03
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 14:10:57.259077 2025] [security2:error] [pid 789:tid 789] [client 209.50.176.90:47161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danged.com"] [uri "/.git/HEAD"] [unique_id "aS85wRlbIV8TmHsX0K6b9AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 07:06:50
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:06:46.046085 2025] [security2:error] [pid 867:tid 867] [client 209.50.176.90:40941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sophcomp.com"] [uri "/.env"] [unique_id "aS6QBjJf9JYneblGKnj-jwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:18:25
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:18:19.361295 2025] [security2:error] [pid 2309:tid 2309] [client 209.50.176.90:43741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abnewhorizons.com"] [uri "/.svn/wc.db"] [unique_id "aS52m54w5cvenAPgrBhACAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2025-12-02 00:53:49
(7 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:27:31
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:27:20.035097 2025] [security2:error] [pid 3091:tid 3091] [client 209.50.176.90:47663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.joecouttswoodsculptor.com"] [uri "/.env"] [unique_id "aSU-OMwo7UP9UAHpo0EGqgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:39:49
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:39:46.197194 2025] [security2:error] [pid 19103:tid 19103] [client 209.50.176.90:30677] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kentuckianacordcutters.com"] [uri "/.env"] [unique_id "aSUzEvGRdnIlpQoH0O9xYQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:20:46
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:20:37.199542 2025] [security2:error] [pid 1817000:tid 1817029] [client 209.50.176.90:41249] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.luckystonebeads.com"] [uri "/.svn/wc.db"] [unique_id "aSUulZiXM9qjzOaPIgQlIQAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:02:15
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:02:08.365583 2025] [security2:error] [pid 3057:tid 3057] [client 209.50.176.90:18175] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hi-niemczuras.net"] [uri "/.env"] [unique_id "aSUOIE3v9JbsEUrJT8T01QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:25:26
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:25:18.955949 2025] [security2:error] [pid 31498:tid 31514] [client 209.50.176.90:25003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sjstauffer.com"] [uri "/.git/HEAD"] [unique_id "aSUFfvow9dE5SYd00VRV-AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:04:16
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.176.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:04:10.347425 2025] [security2:error] [pid 2967:tid 2967] [client 209.50.176.90:47251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.baldventure.com.tomthomasplumbing.com"] [uri "/.git/HEAD"] [unique_id "aSP1Wq-YZwhA04KrpVHAxgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack