π«π·
ELYAZ
2026-06-12 02:36:14
(3 days ago)
(y4) Failed scan -byebye- from 216.26.247.170 (ES/Spain/-): (CF_ENABLE)
Hacking
π¨π
4server
2026-06-10 21:59:56
(4 days ago)
[WedJun1023:59:50.6701642026][security2:error][pid4159080:tid4159351][client216.26.247.170:0]ModSecu ...
show more
[WedJun1023:59:50.6701642026][security2:error][pid4159080:tid4159351][client216.26.247.170:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?i\)\(127\\\\\\\\.0\\\\\\\\.0\\\\\\\\.1\|localhost\|0\\\\\\\\.0\\\\\\\\.0\\\\\\\\.0\|169\\\\\\\\.254\\\\\\\\.169\\\\\\\\.254\)\"atARGS:pwd.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"20\"][id\"990003\"][msg\"PossibleSSRF/internalhostaccessattempt\"][hostname\"xn--tirascarph-ieb.ch\"][uri\"/wp-login.php\"][unique_id\"aineVpSYOHvEl5Ba84a_IAAAAQY\"]\,referer:https://xn--tirascarph-ieb.ch/wp-login.php
show less
Hacking
Web App Attack
π¬π§
Steve
2026-05-05 17:48:04
(1 month ago)
Repeated attempts against wordpress site
Brute-Force
Web App Attack
Anonymous
2026-01-03 13:32:33
(5 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.03 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2026.01.03 is noted in report timestamp
show less
Hacking
Brute-Force
πͺπΈ
10dencehispahard SL
2025-12-29 09:30:04
(5 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
π΅π±
sefinek.net
2025-12-21 22:08:27
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Linux i686; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π΅π±
sefinek.net
2025-12-12 16:45:30
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-03 04:41:15
(6 months ago)
(mod_security) mod_security (id:210740) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210740) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 23:41:08.170383 2025] [security2:error] [pid 18703:tid 18712] [client 216.26.247.170:23389] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/Proxy-Connection/" at TX:header_name. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "33"] [id "210740"] [rev "2"] [msg "COMODO WAF: HTTP header is restricted by policy||vtweaversguild.org|F|4"] [data "/Proxy-Connection/"] [severity "WARNING"] [tag "CWAF"] [tag "HTTP"] [hostname "vtweaversguild.org"] [uri "/g_book.cgi"] [unique_id "aS-_ZDnqI4ZRPXHC0lZ1PAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 09:39:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:39:12.887692 2025] [security2:error] [pid 18088:tid 18088] [client 216.26.247.170:47525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.altoshp.com"] [uri "/.git/HEAD"] [unique_id "aSQnwGUErAcl7mB7vr2SnAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 08:50:40
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:50:26.384809 2025] [security2:error] [pid 3690694:tid 3690694] [client 216.26.247.170:20225] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.katharinanitzpon.com"] [uri "/.env"] [unique_id "aSQcUptlVoKeJ6YcE-3WMwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:34:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:34:07.018504 2025] [security2:error] [pid 17411:tid 17411] [client 216.26.247.170:17239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usoilinc.soviaenterprises.com"] [uri "/.env"] [unique_id "aSQKbxuutmc3s0wUbK3atwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:38:26
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:38:20.864567 2025] [security2:error] [pid 29606:tid 29606] [client 216.26.247.170:60071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angelpalomino.com"] [uri "/.svn/wc.db"] [unique_id "aSP9XMJamXUoy63M9ZI5RAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 05:19:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:19:11.479512 2025] [security2:error] [pid 26805:tid 26805] [client 216.26.247.170:53647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dentistholidaycards.com"] [uri "/.env"] [unique_id "aSPqz2MegksGM7chq7AAnwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 03:00:18
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.247.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:00:03.460861 2025] [security2:error] [pid 22050:tid 22050] [client 216.26.247.170:25573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.northamericantrucking.com"] [uri "/.git/HEAD"] [unique_id "aSPKM8ZQbyaQNdoz2sFCpQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 18:28:31
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/13 12:27:44
Port Scan
Brute-Force
Exploited Host
Web App Attack