πΊπΈ
LotPhantom
2025-10-05 19:51:07
(7 months ago)
2025-10-05T19:51:07.176993+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1 ...
show more
2025-10-05T19:51:07.176993+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=212.30.37.59 DST=157.230.217.55 LEN=436 TOS=0x00 PREC=0x40 TTL=117 ID=7122 PROTO=UDP SPT=29510 DPT=5061 LEN=416
2025-10-05T19:51:07.177020+00:00 bridginggaps kernel: [UFW BLOCK] IN=eth0 OUT= MAC=2e:bc:64:1d:2c:e1:fe:00:00:00:01:01:08:00 SRC=212.30.37.59 DST=157.230.217.55 LEN=436 TOS=0x00 PREC=0x40 TTL=117 ID=7121 PROTO=UDP SPT=55010 DPT=5060 LEN=416
...
show less
Port Scan
Hacking
π©πͺ
QUADEMU Abuse Dpt
2025-10-05 19:34:14
(7 months ago)
Noxious/Nuisible/Π²ΡΠ΅Π΄ΠΎΠ½ΠΎΡΠ½ΡΠΉ Host.
Port Scan
Exploited Host
π―π΅
Valhalla
2025-09-25 13:03:52
(8 months ago)
/back/index.zip
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-23 18:09:21
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 23 14:09:17.350591 2025] [security2:error] [pid 14957:tid 14966] [client 212.30.37.59:33873] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ethniclivesmatter.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ethniclivesmatter.com"] [uri "/backups/backup.sql"] [unique_id "aNLiTRt9TSDZ17rTJ2dPhwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-20 22:12:32
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 20 18:12:26.216113 2025] [security2:error] [pid 2019:tid 2019] [client 212.30.37.59:24697] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crypto-stamps.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crypto-stamps.com"] [uri "/old/wallet.dat"] [unique_id "aM8mylrsERne3GG5Tvsg-wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
pinguin
2025-09-17 08:11:02
(8 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /backup/bak.zip
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π°π·
forgeban
2025-09-16 17:27:52
(8 months ago)
Honeypot hit: Empty payload (likely service probe); 5038 [9] TCP
Port Scan
π©πͺ
hbrks
2025-09-13 18:51:15
(8 months ago)
1 attack(s) detected since 2025-09-13T18:38:06.145Z, such as these: {"event":"nginx_block","ip":"212 ...
show more
1 attack(s) detected since 2025-09-13T18:38:06.145Z, such as these: {"event":"nginx_block","ip":"212.30.37.59","host":"marche-be.com","request":"GET / HTTP/1.1","user_agent":"","reason":"service:unknow","timestamp":"2025-09-13T18:38:06 00:00","logentry":"marche-be.com 212.30.37.59 - - [13/Sep/2025:18:38:06 0000] \"GET / HTTP/1.1\" 444 0 \"-\" \"-\" \"-\" \"matched:service:unknow\""} Report Details: https://p4u.xyz/8EWH6GHNN2I/1IP Details: https://p4u.xyz/8EWH6GHNN2I/2
show less
Web Spam
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-09-06 14:09:09
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 10:09:04.547982 2025] [security2:error] [pid 11986:tid 11986] [client 212.30.37.59:61461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ezsmiledental.com"] [uri "/back/sftp-config.json"] [unique_id "aLxAgEKHusNLfy7jcDsHFwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-26 00:04:25
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 25 20:04:16.176565 2025] [security2:error] [pid 22976:tid 22976] [client 212.30.37.59:23353] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinsquaretrade.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinsquaretrade.com"] [uri "/old/www.sql"] [unique_id "aKz6AJyt19Sk6kFxB1XhCwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-13 05:37:53
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 13 01:37:46.028617 2025] [security2:error] [pid 27337:tid 27337] [client 212.30.37.59:63893] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctoredwinalvarez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctoredwinalvarez.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aJwkqswvCbqRegBW9xhOUQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2025-08-13 04:21:30
(9 months ago)
1.526 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-08-12 08:46:06
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 12 04:45:58.511670 2025] [security2:error] [pid 28601:tid 28601] [client 212.30.37.59:45433] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.digi-estudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.digi-estudio.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aJr_RspUEJjFR26aqO8-rgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2025-08-09 08:20:01
(9 months ago)
2.000 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-08-09 03:05:30
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 08 23:05:25.824990 2025] [security2:error] [pid 31241:tid 31241] [client 212.30.37.59:32497] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.silalaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.silalaw.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aJa69cGcXE_MhIOvqZwtRwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack