๐จ๐ฆ
1gz
2026-05-11 01:06:55
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST me ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST method)
Endpoint: /xmlrpc.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_1) AppleWebKit/536.39 (KHTML, like Gecko111) Chrome/97.1 Safari/536.55
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
LRob.fr
2026-04-12 04:45:09
(2 months ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2025-12-23 06:44:36
(5 months ago)
Cloudflare WAF: Request Path: /multivol_blackryu Request Query: Host: elhacker.net userAgent: Mozil ...
show more
Cloudflare WAF: Request Path: /multivol_blackryu Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: BTTGROUP-AS Country: US Method: GET Timestamp: 2025-12-23T06:44:36Z ruleId: 12b9aecf1f6245b29d7e842bf35a42a0. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2025-12-23 05:59:31
(5 months ago)
Cloudflare WAF: Request Path: /multivol_blackryu Request Query: Host: elhacker.net userAgent: Mozil ...
show more
Cloudflare WAF: Request Path: /multivol_blackryu Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: BTTGROUP-AS Country: US Method: GET Timestamp: 2025-12-23T05:59:31Z ruleId: 12b9aecf1f6245b29d7e842bf35a42a0. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2025-12-18 06:44:22
(5 months ago)
Cloudflare WAF: Request Path: /ptbt_apdos Request Query: Host: elhacker.net userAgent: Mozilla/5.0 ...
show more
Cloudflare WAF: Request Path: /ptbt_apdos Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: BTTGROUP-AS Country: US Method: GET Timestamp: 2025-12-18T06:44:22Z ruleId: 12b9aecf1f6245b29d7e842bf35a42a0. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2025-12-18 05:44:24
(5 months ago)
Cloudflare WAF: Request Path: /ptbt_apdos Request Query: Host: elhacker.net userAgent: Mozilla/5.0 ...
show more
Cloudflare WAF: Request Path: /ptbt_apdos Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: BTTGROUP-AS Country: US Method: GET Timestamp: 2025-12-18T05:44:24Z ruleId: 12b9aecf1f6245b29d7e842bf35a42a0. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2025-12-18 04:44:27
(5 months ago)
Cloudflare WAF: Request Path: /ptbt_apdos Request Query: Host: elhacker.net userAgent: Mozilla/5.0 ...
show more
Cloudflare WAF: Request Path: /ptbt_apdos Request Query: Host: elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Action: block Source: l7ddos ASN Description: BTTGROUP-AS Country: US Method: GET Timestamp: 2025-12-18T04:44:27Z ruleId: 12b9aecf1f6245b29d7e842bf35a42a0. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐จ๐ญ
Zeprax
2025-12-17 19:52:54
(5 months ago)
Layer 7 Flood Detected
DDoS Attack
๐บ๐ธ
COMPLEX
2025-12-10 17:21:06
(6 months ago)
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
ASN: 35830 (BTTGROUP-AS)
Protocol: HT ...
show more
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
ASN: 35830 (BTTGROUP-AS)
Protocol: HTTP/2 (GET method)
Endpoint: /
show less
DDoS Attack
Bad Web Bot
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-09 20:27:52
(6 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ต๐น
PTnet
2025-12-09 10:03:41
(6 months ago)
DDoS Attack (jail:haproxy-badreq)
DDoS Attack
Exploited Host
๐ฉ๐ช
PTnet
2025-12-09 02:07:52
(6 months ago)
DDoS Attack (jail:haproxy-https-flood)
DDoS Attack
Exploited Host
๐ต๐น
PTnet
2025-12-09 02:07:52
(6 months ago)
DDoS Attack (jail:haproxy-https-flood)
DDoS Attack
Exploited Host
๐ช๐ธ
Mugen
2025-04-02 05:44:03
(1 year ago)
Unauthorized VPN login attempts
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-03-28 12:27:09
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 212.119.41.51 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 212.119.41.51 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 28 08:27:05.663792 2025] [security2:error] [pid 23070:tid 23070] [client 212.119.41.51:29051] [client 212.119.41.51] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "Z-aVmdhrWL5VeYXH0U_FTQAAAA8"], referer: https://jolankagroup.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack