🇫🇷
Sklurk
2026-09-01 06:05:34
(4 days ago)
Web App Attack
Web App Attack
🇬🇧
gigatech
2026-08-25 00:30:06
(1 week ago)
Webserver Probing
Web App Attack
Anonymous
2026-08-21 05:03:12
(2 weeks ago)
Botnets flood DDoS activity
DDoS Attack
🇫🇷
Sklurk
2026-08-02 02:56:50
(1 month ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-06-23 04:07:06
(2 months ago)
Web App Attack
Web App Attack
🇪🇸
librebit
2026-06-18 09:09:24
(2 months ago)
Brute force
Brute-Force
🇵🇱
sefinek.net
2026-02-10 08:01:22
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇯🇵
ki3
2025-11-28 15:24:47
(9 months ago)
Fail2Ban: Web App Attacks and Forum Spam 216.26.238.131 1764343486.0(JST)
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-27 22:20:34
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 17:20:28.076386 2025] [security2:error] [pid 25811:tid 25811] [client 216.26.238.131:32519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "humbliaslaw.com"] [uri "/.env"] [unique_id "aSjOrB07Aix4LZvpkgC27gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 09:01:20
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:01:16.273793 2025] [security2:error] [pid 10859:tid 10859] [client 216.26.238.131:34901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.harrygant.com"] [uri "/.svn/wc.db"] [unique_id "aSQe3I26Fz5m92Dce0k6NQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 08:21:26
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:21:22.751490 2025] [security2:error] [pid 10102:tid 10102] [client 216.26.238.131:58593] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.fairfieldfarms.net"] [uri "/.svn/wc.db"] [unique_id "aSQVgo_VRYPOzd7fXOh9DQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 07:19:54
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:19:41.425773 2025] [security2:error] [pid 5590:tid 5590] [client 216.26.238.131:44643] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.filardi.org"] [uri "/.svn/wc.db"] [unique_id "aSQHDQYCw30cGJlsaroP6QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
boxed-it
2025-11-24 05:37:57
(9 months ago)
GET /.svn/wc.db (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 04:38:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.238.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:38:47.386226 2025] [security2:error] [pid 27670:tid 27670] [client 216.26.238.131:24839] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lsd36.com"] [uri "/.git/HEAD"] [unique_id "aSPhV7OViXpGlYmFWdRn7AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
octageeks.com
2025-11-13 05:07:43
(9 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack