๐ซ๐ฎ
inlink.ltd
2026-06-05 11:45:27
(2 weeks ago)
Known malicious PHP file or CMS probe
Web App Attack
๐ฉ๐ช
kranem
2026-02-25 06:02:35
(3 months ago)
Triggered Cloudflare WAF from CA.
Action taken: BLOCK
ASN: 200373 (DREI-K-TECH-GMBH)
Protocol: HTTP/ ...
show more
Triggered Cloudflare WAF from CA.
Action taken: BLOCK
ASN: 200373 (DREI-K-TECH-GMBH)
Protocol: HTTP/2 (GET method)
Endpoint: /auth/login
Timestamp: 2026-02-25T04:53:11Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2025-12-27 19:44:09
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-26 10:20:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:20:08.158676 2025] [security2:error] [pid 19461:tid 19461] [client 216.26.250.139:30691] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pete-n-sheila.net"] [uri "/.svn/wc.db"] [unique_id "aSbUWPTE5p9OoYKukx07jAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 07:12:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 02:12:29.753708 2025] [security2:error] [pid 22705:tid 22705] [client 216.26.250.139:27235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.belgiophar.com"] [uri "/.git/HEAD"] [unique_id "aSaoXa4HQVXLikl6qI7A_gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 03:22:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 22:21:53.858501 2025] [security2:error] [pid 24096:tid 24096] [client 216.26.250.139:25949] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.monogay.org"] [uri "/.svn/wc.db"] [unique_id "aSZyUchlDIWvsjp5n5wHYAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-26 02:34:28
(6 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:23:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 216.26.250.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:23:46.597322 2025] [security2:error] [pid 13895:tid 13915] [client 216.26.250.139:37411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.titanweb.com"] [uri "/.git/HEAD"] [unique_id "aSU9YsqATJ-N2rrGOLaKfQAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-02 17:13:26
(7 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/02 06:48:08
Port Scan
Brute-Force
Exploited Host
Web App Attack