๐ฎ๐ฉ
securejdprop
2026-10-06 20:33:43
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 67).
show less
Hacking
Web App Attack
๐บ๐ธ
1gz
2026-09-14 15:52:56
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /script.js
UA: Lightpanda/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
drewf.ink
2026-09-04 12:16:12
(1 month ago)
[12:16] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gatew ...
show more
[12:16] Attempted HTTPS access to the GlobalProtect prelogin endpoint on the web honeypot (VPN gateway fingerprinting/recon)
show less
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-13 04:06:11
(1 month ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-02 04:26:14
(2 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ซ๐ท
Sklurk
2026-08-01 01:26:56
(2 months ago)
Web App Attack
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 months ago)
Apache probe; attempts=39; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-23 06:04:04
(2 months ago)
Wordfence waf block on fairregistry
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 05:42:05
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 00:41:59.108497 2025] [security2:error] [pid 14092:tid 14092] [client 216.26.233.61:45019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.memotronic.com"] [uri "/.env"] [unique_id "aSaTJ6XwryWD0BYpldjRXAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 03:08:25
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:08:21.391783 2025] [security2:error] [pid 22655:tid 22655] [client 216.26.233.61:59787] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nutandboltguy.com"] [uri "/.env"] [unique_id "aSZvJeQHJrD1NSl8DwwG2wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 01:12:38
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 20:12:34.775736 2025] [security2:error] [pid 7687:tid 7687] [client 216.26.233.61:22429] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sabbathschoolguide.com"] [uri "/.env"] [unique_id "aSZUAkm07m6SEU-P9eeTgwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 00:53:10
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 19:53:08.340006 2025] [security2:error] [pid 16306:tid 16306] [client 216.26.233.61:35901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usbea.liftreading.com"] [uri "/.git/HEAD"] [unique_id "aSZPdL7uyJO5uD_vSe8tGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:03:50
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:03:44.318901 2025] [security2:error] [pid 27284:tid 27284] [client 216.26.233.61:41563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.rosemeadefarms.com"] [uri "/.svn/wc.db"] [unique_id "aSQRYFqo7SnEi_Mixfqu4QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 00:48:20
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.233.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 19:47:26.908260 2025] [security2:error] [pid 11873:tid 11873] [client 216.26.233.61:31749] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jperverseincentives.com"] [uri "/.git/HEAD"] [unique_id "aSOrHrJ3QLAGw09XMvM7IQAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2025-11-01 12:18:48
(11 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack