πΊπΈ
ctidrv
2026-09-01 11:56:37
(1 day ago)
Honeypot detection. Threat score: 85/100. Collector: wp_login. | Request: POST /wp-login.php | Crede ...
show more
Honeypot detection. Threat score: 85/100. Collector: wp_login. | Request: POST /wp-login.php | Credentials captured: user=lefeywev | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15 | rDNS: 216.26.225.73 | Reasons: wp_login_probe, wp_credentials_submitted
show less
Brute-Force
Bad Web Bot
π©πͺ
dom4k
2026-08-17 05:16:40
(2 weeks ago)
216.26.225.73 - - [17/Aug/2026:05:16:39 +0000] "GET /.git/./config HTTP/1.1" 444 0 "-" "Mozilla/5.0 ...
show more
216.26.225.73 - - [17/Aug/2026:05:16:39 +0000] "GET /.git/./config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web Spam
Bad Web Bot
Web App Attack
πΊπΈ
lostswordfish.com
2026-08-09 11:54:04
(3 weeks ago)
Wordfence waf block on uvfousor WPIDD
Web App Attack
Anonymous
2026-08-05 06:53:57
(4 weeks ago)
Banned by SPAMHAUS DROP list
DDoS Attack
Hacking
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-08-05 06:50:58
(4 weeks ago)
[WedAug0508:50:53.5667192026][security2:error][pid2337576:tid2337595][client216.26.225.73:0]ModSecur ...
show more
[WedAug0508:50:53.5667192026][security2:error][pid2337576:tid2337595][client216.26.225.73:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"mail.gustotondo.ch\"][uri\"/xmlrpc.php\"][unique_id\"anLdTXG2fDVTiahCkDZM4AAAAAY\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
apislytics
2026-08-04 13:13:24
(4 weeks ago)
Automatic hard ban after repeated rate-limit abuse
Brute-Force
π§πͺ
voormedia
2026-08-03 12:33:29
(4 weeks ago)
Accessed trap at '/wp-login.php'
Web App Attack
π«π·
Sklurk
2026-07-09 00:57:45
(1 month ago)
Web App Attack
Web App Attack
π¬π§
PeravixGroup
2026-06-09 21:22:15
(2 months ago)
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity ...
show more
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
πΊπΈ
myagent.site
2026-01-15 08:41:32
(7 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
π΅π±
sefinek.net
2026-01-02 05:24:29
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π©πͺ
Petros Stefanakis
2025-12-16 10:53:28
(8 months ago)
(mod_security) mod_security triggered on hostname [redacted] 216.26.225.73 (US/United States/-)
SQL Injection
Anonymous
2025-12-12 16:55:21
(8 months ago)
botnet
DDoS Attack
πΊπΈ
TPI-Abuse
2025-11-26 05:33:55
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.225.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.225.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:33:48.983245 2025] [security2:error] [pid 16184:tid 16184] [client 216.26.225.73:58743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.prayers4america.com"] [uri "/.env"] [unique_id "aSaRPKdA-c8zYc1hN2AuTwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-26 01:51:31
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.225.73 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.225.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:51:26.359600 2025] [security2:error] [pid 28967:tid 28967] [client 216.26.225.73:10669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.elegantweddinginvitations.net"] [uri "/.git/HEAD"] [unique_id "aSZdHphTK7QZb5bYcKs5wAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack