๐ซ๐ท
mrcrassi
2026-07-22 02:17:46
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
dtorrer
2026-06-02 21:20:45
(1 month ago)
Client attempted to submit spam on a website post.
Blog Spam
๐ซ๐ท
dynamix
2026-01-17 10:38:49
(6 months ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:30
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-02 22:55:45
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 17:55:39.103600 2025] [security2:error] [pid 26271:tid 26271] [client 209.50.185.99:17241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aisoftwaretools.com"] [uri "/.svn/wc.db"] [unique_id "aS9ua6I96HkCiUYqEm-3rgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 07:49:34
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:49:30.207673 2025] [security2:error] [pid 29164:tid 29164] [client 209.50.185.99:27765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drwolberg.com"] [uri "/.git/HEAD"] [unique_id "aS6aChrMHGOl__84VquECAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-11-25 23:04:28
(7 months ago)
Auto-ban: >3000 req/min op 2025-11-25
Hacking
Web App Attack
SSH
๐ฌ๐ง
Swiptly
2025-11-25 20:50:51
(7 months ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack
๐บ๐ธ
CBJ
2025-11-25 03:52:50
(7 months ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:29:14
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:29:06.157263 2025] [security2:error] [pid 32735:tid 338] [client 209.50.185.99:41579] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.deyyoungart.com"] [uri "/.svn/wc.db"] [unique_id "aSUiguyRrmvyed2G3rXIvAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:27:08
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:27:02.778751 2025] [security2:error] [pid 5162:tid 5162] [client 209.50.185.99:13457] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dantobinlaw.com"] [uri "/.env"] [unique_id "aSUT9puEHAbpOnqAB6YG6AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:29:35
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.185.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:29:31.715792 2025] [security2:error] [pid 16321:tid 16321] [client 209.50.185.99:35487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brunswickcemeteries.org"] [uri "/.svn/wc.db"] [unique_id "aSUGe6wfGw0Kh70dsafzrgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2025-11-24 20:08:33
(7 months ago)
GET /.git/HEAD HTTP/1.1
Web App Attack