🇺🇸
Ben Schoolland
2026-09-11 10:58:51
(1 hour ago)
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legiti ...
show more
Requested known WordPress backdoor/scanner-only paths (config backups, .env, .git/config). No legitimate use.
show less
Bad Web Bot
Web App Attack
🇨🇿
lp
2026-09-03 00:21:11
(1 week ago)
Unauthorized VPN login attempts: 21 attempts were recorded from 216.26.228.133
2026-09-03T01:39:10+0 ...
show more
Unauthorized VPN login attempts: 21 attempts were recorded from 216.26.228.133
2026-09-03T01:39:10+02:00 vpn Access-Reject 'baer' station: 216.26.228.133 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T01:40:19+02:00 vpn Access-Reject 'sche' station: 216.26.228.133 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T01:41:59+02:00 vpn Access-Reject 'ghanem' station: 216.26.228.133 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T01:43:31+02:00 vpn Access-Reject 'administrator' station: 216.26.228.133 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2026-09-03T01:46:40+02:00 vpn Access-Reject 'ggg' station: 216.26.228.133 auth-type: - realm: vse.cz nas: <re
show less
Brute-Force
Web App Attack
🇩🇪
Goetz
2026-09-01 09:09:55
(1 week ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
🇫🇷
Sklurk
2026-09-01 03:03:42
(1 week ago)
Web App Attack
Web App Attack
🇺🇸
1gz
2026-08-29 21:14:29
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /script.js
UA: Lightpanda/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇪🇸
librebit
2026-06-24 03:22:23
(2 months ago)
Brute force
Brute-Force
Anonymous
2026-01-22 05:13:43
(7 months ago)
botnet
DDoS Attack
🇱🇻
garmtech.com
2026-01-13 10:07:49
(7 months ago)
IM360 WAF: SQL Injection Attack: Common DB Names Detected
SQL Injection
🇺🇸
TPI-Abuse
2025-12-27 20:04:09
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 27 15:04:02.771835 2025] [security2:error] [pid 9828:tid 9828] [client 216.26.228.133:54903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bostonamerican.com"] [uri "/.git/HEAD"] [unique_id "aVA7spIEq9jdnt_xRVQYQgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 09:34:48
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:30:48.185026 2025] [security2:error] [pid 9155:tid 9382] [client 216.26.228.133:60237] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gitlab.transitionalcareservices.com"] [uri "/.svn/wc.db"] [unique_id "aSQlyE0B2wPuSERayWCHyQAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 08:01:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:01:21.754170 2025] [security2:error] [pid 28097:tid 28097] [client 216.26.228.133:48763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.niximperial.biz"] [uri "/.svn/wc.db"] [unique_id "aSQQ0ecdejHkwzwylvoAdAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:43:24
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:43:07.866315 2025] [security2:error] [pid 2736:tid 2736] [client 216.26.228.133:30475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.female-strippers-los-angeles.com"] [uri "/.svn/wc.db"] [unique_id "aSQMi0efKWoB73xPrdJ2lwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:21:42
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:21:37.712982 2025] [security2:error] [pid 5223:tid 5251] [client 216.26.228.133:11861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arthansl.com"] [uri "/.env"] [unique_id "aSQHgWBLaC45odtmKAm1NgAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:04:39
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:04:30.118342 2025] [security2:error] [pid 10683:tid 10683] [client 216.26.228.133:56661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adsdry.com.questiondezyn.com"] [uri "/.git/HEAD"] [unique_id "aSQDftrMXRUvZCCH4Cl2wgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 05:41:10
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.228.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:41:03.998952 2025] [security2:error] [pid 18501:tid 18501] [client 216.26.228.133:27691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mmmetalizing.com"] [uri "/.git/HEAD"] [unique_id "aSPv7xsHIq_C_LY83aei_wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack