π²π½
octageeks.com
2026-07-19 04:18:18
(2 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
πΊπΈ
RH5
2026-07-19 00:53:35
(2 days ago)
Path fuzzing with repeated /-/ segments (/-/-/-/-/-/-/-/-/-/-/) (UTC 2026-07-19 00:53)
Web App Attack
π«π·
pm33
2026-07-15 16:37:45
(6 days ago)
Wordpress login attempts
Brute-Force
πΊπΈ
bpolson
2026-07-15 04:52:04
(6 days ago)
WordPress Hacking/Scanning. (s1)
Hacking
Web App Attack
π¬π§
PeravixGroup
2026-05-08 06:46:44
(2 months ago)
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severit ...
show more
Honeypot detection: Kubernetes API unauthorized access / cluster abuse attempt on port 6443. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
π±π»
garmtech.com
2026-04-18 11:16:13
(3 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 21:10:48
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:10:39.935340 2026] [security2:error] [pid 5966:tid 5966] [client 209.50.184.70:56487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gapguardian.shop"] [uri "/admin/.git/config"] [unique_id "aYpNTyU31mCkQrGW9hcH0QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 20:08:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:08:10.685961 2026] [security2:error] [pid 21771:tid 21771] [client 209.50.184.70:29165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galengetting.com"] [uri "/admin/.env"] [unique_id "aYo-qrdgnE107Xido_8VuAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 18:55:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 13:55:34.100417 2026] [security2:error] [pid 16877:tid 16877] [client 209.50.184.70:27309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fydelity.net"] [uri "/backup/.git/config"] [unique_id "aYotpgGCaKVMkP0PFHGQGwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-09 09:38:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 04:38:21.286605 2026] [security2:error] [pid 28731:tid 28731] [client 209.50.184.70:44439] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fullyevil.com"] [uri "/.env.production"] [unique_id "aYmrDdBhlO9gDCPXKO1rSAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2025-12-24 16:00:00
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π©πͺ
kjaerulff
2025-12-02 16:29:55
(7 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
π¬π§
thetomtaylor.co.uk
2025-12-02 00:53:26
(7 months ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer
... [wa02]
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 09:32:23
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:32:17.163749 2025] [security2:error] [pid 3795703:tid 3795703] [client 209.50.184.70:50955] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lakewoodranchhairsalon.com"] [uri "/.env"] [unique_id "aSQmIU4t5BfcDzJsVe8aSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 08:59:46
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.184.70 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:59:42.336835 2025] [security2:error] [pid 12993:tid 12993] [client 209.50.184.70:57233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "msbook4kids.banis-associates.com"] [uri "/.git/HEAD"] [unique_id "aSQefmKKNPgzZrjswXXa1gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack