๐ซ๐ท
uhlhosting
2025-12-09 01:09:43
(5 months ago)
taxigut.ch 212.30.37.28 - - [09/Dec/2025:02:09:37.507873 +0100] "GET /wp-includes/assets/autoload_cl ...
show more
taxigut.ch 212.30.37.28 - - [09/Dec/2025:02:09:37.507873 +0100] "GET /wp-includes/assets/autoload_classmap.php HTTP/1.1" 403 199 "-" "-" aTd20dK8BdfxkBcXsZvIqQAAAFA "-" /apache/20251209/20251209-0209/20251209-020937-aTd20dK8BdfxkBcXsZvIqQAAAFA 0 1120 md5:a8d2e90e9409ab6ab61ae2b898f63dc6
taxigut.ch 212.30.37.28 - - [09/Dec/2025:02:09:38.937118 +0100] "GET /wp-includes/SimplePie/Exception-wp.php HTTP/1.1" 403 199 "-" "-" aTd20tK8BdfxkBcXsZvIsAAAAEQ "-" /apache/20251209/20251209-0209/20251209-020938-aTd20tK8BdfxkBcXsZvIsAAAAEQ 0 1111 md5:ea63c1ca0bbc3e6e213b17fb8eee7a28
taxigut.ch 212.30.37.28 - - [09/Dec/2025:02:09:39.347043 +0100] "GET /wp-includes/rest-api/autoload_classmap.php HTTP/1.1" 403 199 "-" "-" aTd209K8BdfxkBcXsZvIsgAAAEs "-" /apache/20251209/20251209-0209/20251209-020939-aTd209K8BdfxkBcXsZvIsgAAAEs 0 1119 md5:81ec0437efc65a9db44378e2daa9d947
taxigut.ch 212.30.37.28 - - [09/Dec/2025:02:09:42.306028 +0100] "GET /.well-known/pki-validation/1.php HTTP/1.1" 403 199 "-" "-" aTd2
...
show less
DDoS Attack
Brute-Force
Anonymous
2025-12-08 20:05:33
(5 months ago)
wordpress-trap
Web App Attack
๐ณ๐ฑ
Site.eu
2025-12-08 11:43:35
(5 months ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฟ
Antinson
2025-12-07 22:46:42
(5 months ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ท๐บ
sms.ru
2025-12-06 02:21:46
(5 months ago)
/wp-admin/css/colors/blue/blue.php
Web App Attack
๐ฌ๐ง
pinguin
2025-11-30 18:38:36
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /latest.zip
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-30 12:29:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 30 07:29:24.451008 2025] [security2:error] [pid 10754:tid 10754] [client 212.30.37.28:21279] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powderriverinc.com"] [uri "/bak/sftp-config.json"] [unique_id "aSw4pCZjYBWgE0xhKMXNrgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-30 12:07:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 30 07:07:10.258335 2025] [security2:error] [pid 14850:tid 14850] [client 212.30.37.28:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sportsbookcommission.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sportsbookcommission.com"] [uri "/restore/www.sql"] [unique_id "aSwzbke2MsCLVi5R3Z1xHwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
BoredBroadcast
2025-11-24 23:45:16
(6 months ago)
VPN brute force: 32 failed auth attempts on 2025-11-24. Automated botnet pattern.
Brute-Force
SSH
๐ฏ๐ต
Valhalla
2025-11-22 02:20:48
(6 months ago)
/old/www.sql
Hacking
Web App Attack
๐บ๐ธ
Penny Packer
2025-11-07 19:55:42
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฉ๐ช
Bedios GmbH
2025-11-05 17:11:36
(6 months ago)
Web App hacking attempt
Web App Attack
๐ฉ๐ช
hbrks
2025-11-04 17:30:14
(6 months ago)
1 attack(s) detected, such as these: {"event":"nginx_block","ip":"212.30.37.28","host":"marche-be.co ...
show more
1 attack(s) detected, such as these: {"event":"nginx_block","ip":"212.30.37.28","host":"marche-be.com","request":"GET / HTTP/1.1","user_agent":"","reason":"service:unknow","timestamp":"2025-11-04T17:30:14 00:00","logentry":"marche-be.com 212.30.37.28 - - [04/Nov/2025:17:30:14 0000] GET / HTTP/1.1 444 0 - - - matched:service:unknow"} * Report Details *: https://p4u.xyz/RWTQXNAC9Y0/1* IP Details *: https://p4u.xyz/RWTQXNAC9Y0/2
show less
Web Spam
Hacking
Bad Web Bot
๐ง๐ช
cmbplf
2025-10-12 07:24:37
(7 months ago)
2.900 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-10 11:26:42
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 07:26:38.809349 2025] [security2:error] [pid 12364:tid 12364] [client 212.30.37.28:37437] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.baliaccommodationpadangpadang.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.baliaccommodationpadangpadang.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aOjtbvSweyRvhcZQE1KjagAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack