๐ต๐ฑ
skoczo
2026-08-11 18:29:16
(1 week ago)
Honeytoken tripped (detected by https://github.com/skoczo/repgate): /wp-login.php
Web App Attack
๐ซ๐ท
Sklurk
2026-07-08 01:35:39
(1 month ago)
Web App Attack
Web App Attack
๐ต๐ฑ
sefinek.net
2026-03-29 11:41:52
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /genshin-stella-mod | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(4 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
myagent.site
2026-02-13 13:09:09
(6 months ago)
Blocking for trying to access an exploit file: /api/.env
Hacking
๐ช๐ธ
10dencehispahard SL
2026-01-26 10:38:05
(6 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
Anonymous
2026-01-05 20:26:01
(7 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.05 is noted in report timestamp
show less
Hacking
Brute-Force
๐ต๐ฑ
sefinek.net
2025-12-16 05:32:50
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 YaBrowser/22.7.0 Yowser/2.5 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
myagent.site
2025-12-08 19:08:46
(8 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-08 18:45:04
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 13:44:54.717342 2025] [security2:error] [pid 12954:tid 12954] [client 216.26.246.12:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.git/HEAD"] [unique_id "aTccpr21IWK4t3anDBCv1gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 14:50:45
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:50:37.666451 2025] [security2:error] [pid 7193:tid 7193] [client 216.26.246.12:22943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robotsinme.org"] [uri "/.git/HEAD"] [unique_id "aTWUPac-vUvDfdPBjdW_HQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 12:05:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 07:05:13.506619 2025] [security2:error] [pid 29707:tid 29732] [client 216.26.246.12:42827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aafm.org"] [uri "/.svn/wc.db"] [unique_id "aTVteSq5XQUJFjJNTI-7HgAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 07:48:43
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 02:48:30.228699 2025] [security2:error] [pid 18330:tid 18330] [client 216.26.246.12:57307] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limobustacoma.com"] [uri "/.env"] [unique_id "aTKOTuh16w5zAIiHcYWGVwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 05:29:55
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 00:29:51.050675 2025] [security2:error] [pid 3627:tid 3627] [client 216.26.246.12:57653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howardsooley.com"] [uri "/.svn/wc.db"] [unique_id "aTJtzyS3zD5JxfCl8ZQxXQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:26:03
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.246.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:25:58.025571 2025] [security2:error] [pid 10619:tid 10699] [client 216.26.246.12:24209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.greaternorthmiamihistory.org"] [uri "/.git/HEAD"] [unique_id "aSVaBgXcnVrJOg7V-2KIjgAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack