๐ฆ๐บ
MAGIC
2026-06-13 01:12:31
(6 days ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-06-10 01:09:35
(1 week ago)
[ns31.kdns.gr] httpd-login-spray-site: sites=savouras.gr; logs=/var/log/httpd/domains/savouras.gr.lo ...
show more
[ns31.kdns.gr] httpd-login-spray-site: sites=savouras.gr; logs=/var/log/httpd/domains/savouras.gr.log; samples=site_wide=true | distinct_ips=17 | /wp-login.php
show less
Hacking
Web App Attack
๐จ๐ฆ
1gz
2026-06-08 12:30:37
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /server/50019179/files
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-20 13:24:49
(4 weeks ago)
(mod_security) mod_security (id:234930) triggered by 212.30.33.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:234930) triggered by 212.30.33.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 09:24:45.244362 2026] [security2:error] [pid 8337:tid 8337] [client 212.30.33.6:23173] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||www.laboquimia.es|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "www.laboquimia.es"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ag22HTwmXzBAQW5FZ026nAAAAB4"], referer: http://www.laboquimia.es/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-20 07:54:23
(4 weeks ago)
212.30.33.6 - - [20/May/2026:10:53:37 +0300] "GET /wp-content/plugins/wp-responsive-menu/inc/js/ace- ...
show more
212.30.33.6 - - [20/May/2026:10:53:37 +0300] "GET /wp-content/plugins/wp-responsive-menu/inc/js/ace-min-noconflict/403x.php HTTP/1.1" 404 704 "-" "Go-http-client/1.1"
212.30.33.6 - - [20/May/2026:10:54:22 +0300] "GET /wp-content/themes/theme-check/theme-check.php HTTP/1.1" 404 704 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
Rayulcifer
2026-05-20 05:35:24
(4 weeks ago)
212.30.33.6 - - [20/May/2026:00:35:17 -0500] "GET /.well-known/index.php HTTP/2.0" 200 886 "http://t ...
show more
212.30.33.6 - - [20/May/2026:00:35:17 -0500] "GET /.well-known/index.php HTTP/2.0" 200 886 "http://tesis.pucp.edu.pe/.well-known/index.php" "Go-http-client/2.0"
212.30.33.6 - - [20/May/2026:00:35:19 -0500] "GET /wp-includes/assets/index.php HTTP/2.0" 200 523 "http://tesis.pucp.edu.pe/wp-includes/assets/index.php" "Go-http-client/2.0"
212.30.33.6 - - [20/May/2026:00:35:20 -0500] "GET /wp-admin/fmadmin.php HTTP/2.0" 200 528 "http://tesis.pucp.edu.pe/wp-admin/fmadmin.php" "Go-http-client/2.0"
212.30.33.6 - - [20/May/2026:00:35:21 -0500] "GET /wp-content/admin.php HTTP/2.0" 200 528 "http://tesis.pucp.edu.pe/wp-content/admin.php" "Go-http-client/2.0"
212.30.33.6 - - [20/May/2026:00:35:22 -0500] "GET /wp-admin/options.php HTTP/2.0" 200 528 "http://tesis.pucp.edu.pe/wp-admin/options.php" "Go-http-client/2.0"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH
๐ฌ๐ง
consul.to
2026-04-21 01:52:08
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
masterguru
2026-04-21 01:00:00
(1 month ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐ช๐ธ
QuiqueB
2026-04-07 12:00:00
(2 months ago)
Failed password for a lot of valid users Microsoft, Entra ID logs, Advance BEC
Brute-Force
Bad Web Bot
Exploited Host
๐ณ๐ฑ
Site.eu
2026-03-14 10:11:30
(3 months ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
paissangroup
2026-03-14 08:20:04
(3 months ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob.fr
2026-03-11 01:15:36
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-10 20:17:46
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.33.6 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.33.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 16:17:40.980015 2026] [security2:error] [pid 1568:tid 1568] [client 212.30.33.6:40059] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||entetanimiento.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "entetanimiento.com"] [uri "/wp-content/plugins/erinyani/asasx.php.bak"] [unique_id "abB8ZPNgMHfWLOA8z9Re1QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-03-10 10:20:04
(3 months ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ฆ
saudetski
2026-03-03 02:08:07
(3 months ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: ES, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: ES, Attack patterns: WordPress scanning, Webshell probing, Malicious User-Agent
show less
Bad Web Bot
Web App Attack