Anonymous
2026-06-16 18:30:04
(2 days ago)
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) ...
show more
Large-scale coordinated botnet (200+k IPs). Attacker: mikhail-smirnov-79830323 (LinkedIn/profile ID) employed by Angara Technologies Group (Explicitly identified himself as enemy a week before attack began) | Attack Signature Blocked: /wishlist/index/add/product/1412/form_key/S828RfoEhjcSBfb6/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Avast/131.0.0.0 | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
tvipper.com
2026-04-02 16:06:44
(2 months ago)
Auto reported by IDS
Hacking
๐ต๐ฑ
dcnet
2026-03-08 00:00:00
(3 months ago)
SSL VPN brute force credential stuffing on FortiGate 100F - unknown user login attempts
Hacking
Brute-Force
๐ช๐ธ
10dencehispahard SL
2026-01-26 09:55:42
(4 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ต๐ฑ
sefinek.net
2026-01-16 06:10:41
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-28 23:57:41
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 18:57:28.332792 2025] [security2:error] [pid 9267:tid 9267] [client 209.50.190.61:27069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityimprinting.com"] [uri "/.env"] [unique_id "aSo26CQ8ImURZQHXJlA2TwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 04:30:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 23:30:09.194902 2025] [security2:error] [pid 9564:tid 9564] [client 209.50.190.61:47799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.yacht-register-holland.com"] [uri "/.git/HEAD"] [unique_id "aSaCUfTOvKiyhkuRADC3kQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 02:59:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 21:59:28.590235 2025] [security2:error] [pid 11563:tid 11563] [client 209.50.190.61:35455] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ruizpuche.com"] [uri "/.env"] [unique_id "aSZtELXp0E772y96UTOXWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:10:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:10:41.902647 2025] [security2:error] [pid 3365544:tid 3365634] [client 209.50.190.61:23125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.manage.aafm.us"] [uri "/.git/HEAD"] [unique_id "aSZTkZ6gyU3zOv0h7a5hVgAAAgw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:46:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:46:51.992639 2025] [security2:error] [pid 2166567:tid 2166567] [client 209.50.190.61:47289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smog-check-central-san-diego.smogsandiego.com"] [uri "/.svn/wc.db"] [unique_id "aSZN-9c2Emxs1JZDTpGC7QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-25 09:48:52
(6 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-11-25 03:47:07
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:46:55.838645 2025] [security2:error] [pid 3409:tid 3409] [client 209.50.190.61:10559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aslproud.com"] [uri "/.git/HEAD"] [unique_id "aSUmrxuvFws-UhuRtX6vEQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-25 02:55:01
(6 months ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:35:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:35:28.908012 2025] [security2:error] [pid 25623:tid 25623] [client 209.50.190.61:30245] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.playerpianosupplies.com.player-care.com"] [uri "/.env"] [unique_id "aSUV8IZ89rvlGCUGn8c32wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:58:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.50.190.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:58:44.665625 2025] [security2:error] [pid 13344:tid 13344] [client 209.50.190.61:13587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.avaliantlife.com"] [uri "/.svn/wc.db"] [unique_id "aSUNVG6v1w75WUR3CLWv5gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack