๐ง๐ช
taivas.nl
2026-09-16 07:02:12
(1 hour ago)
Bad_requests
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-16 04:43:14
(3 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 23.98.157.29 - - [16/Sep/2026:06:43:07 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 58811 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:54:40
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 23.98.157.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.98.157.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:54:33.526890 2026] [security2:error] [pid 12992:tid 13019] [client 23.98.157.29:1228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adventistdeathconfusion.com.mylordsday.com"] [uri "/.git/config"] [unique_id "aqmUaZp3m5-GjkRyLfGfnwAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
slay3r9903
2026-09-15 10:10:49
(22 hours ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
๐ต๐ฑ
gandaflux
2026-09-15 07:02:07
(1 day ago)
23.98.157.29 [redacted-domain] - [15/Sep/2026:09:00:03 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 ...
show more
23.98.157.29 [redacted-domain] - [15/Sep/2026:09:00:03 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
23.98.157.29 [redacted-domain] - [15/Sep/2026:09:01:30 +0200] "GET /wp-config.php~ HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
23.98.157.29 [redacted-domain] - [15/Sep/2026:09:02:06 +0200] "GET /wp-config.php.save HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-15 03:57:01
(1 day ago)
Faked HTTP referer string using numeric IP address of destination host instead of host name.
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-09-14 16:04:27
(1 day ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-13 04:57:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 23.98.157.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.98.157.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 00:57:31.683477 2026] [security2:error] [pid 22795:tid 22795] [client 23.98.157.29:23375] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drayvian.com"] [uri "/wp-config.php~"] [unique_id "aqYtO_r65xUYdvoDNylq0QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mueller-nils.com
2026-09-13 03:55:58
(3 days ago)
Sep 13 05:55:46 [host] kernel: [12380415.720122] [UFW BLOCK] IN=venet0 OUT= MAC= SRC=23.98.157.29 DS ...
show more
Sep 13 05:55:46 [host] kernel: [12380415.720122] [UFW BLOCK] IN=venet0 OUT= MAC= SRC=23.98.157.29 DST=[munged] LEN=60 TOS=0x00 PREC=0x00 TTL=39 ID=9882 DF PROTO=TCP SPT=23236 DPT=3000 WINDOW=64240 RES=0x00 SYN URGP=0 Sep 13 05:55:47 [host] kernel: [1
show less
Port Scan
๐ฎ๐น
VHosting
2026-09-12 23:20:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ช๐ธ
scm
2026-09-08 04:12:59
(1 week ago)
Web App Attack
๐ซ๐ท
mrcrassi
2026-09-08 03:57:17
(1 week ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (POS ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (POST method)
Endpoint: /en
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/122.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
MAGIC
2024-02-01 03:05:59
(2 years ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฒ๐น
Malta
2024-01-30 12:50:35
(2 years ago)
23.98.157.29 - - [30/Jan/2024:13:50:35 +0100] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT 1 ...
show more
23.98.157.29 - - [30/Jan/2024:13:50:35 +0100] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36"
Brute-force password attempt
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2024-01-21 22:34:56
(2 years ago)
WP xmlrpc [2024-01-21T23:34:56+01:00]
Hacking
Web App Attack