🇩🇪
palla89
2026-09-07 11:25:51
(22 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 2607:f298:6:a044::f77:bdc9 (gotgrace.co ...
show more
(mod_security) mod_security triggered on hostname [redacted] 2607:f298:6:a044::f77:bdc9 (gotgrace.com)
show less
SQL Injection
🇩🇪
YF
2026-09-07 09:00:14
(1 day ago)
WordPress content enumeration
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:57:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:57:44.147674 2026] [security2:error] [pid 4057:tid 4057] [client 2607:f298:6:a044::f77:bdc9:59578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batesstrategygroup.com"] [uri "/wp-config.php.bak"] [unique_id "ap5ESGgR0SQljamnU-rCkQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Mehmet_The_Script_Kiddie
2026-09-07 04:21:22
(1 day ago)
CloudFlare WAF REPORT: /?rest_route=/batch/v1
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:55:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:55:35.835079 2026] [security2:error] [pid 20281:tid 20298] [client 2607:f298:6:a044::f77:bdc9:50864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vinylnotespodcast.com"] [uri "/wp-config.php.bak"] [unique_id "ap41tzOUPJDtw4vaIb-P2gAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:04:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:04:34.597778 2026] [security2:error] [pid 25087:tid 25087] [client 2607:f298:6:a044::f77:bdc9:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "duct.cloudex.click"] [uri "/.env"] [unique_id "ap4pwpGoccFGGoJDWSUb9AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
BlueWire Hosting
2026-09-07 02:39:10
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-09-07 02:29:06
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:08:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:08:05.073757 2026] [security2:error] [pid 14666:tid 14666] [client 2607:f298:6:a044::f77:bdc9:59736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hydrometal-js.com"] [uri "/wp-config.php.bak"] [unique_id "ap4OdfOuL6q_Ql6EIhwm_AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:11:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:11:52.407106 2026] [security2:error] [pid 23635:tid 23635] [client 2607:f298:6:a044::f77:bdc9:59656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.michaelthompson.biz"] [uri "/wp-config.php.bak"] [unique_id "ap4BSG7LHMqK4MbzLIlPnAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 00:10:08
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 2607:f298:6:a044::f77:bdc9 (Unknown)
SQL Injection
🇮🇩
soc-yk
2026-09-07 00:06:18
(1 day ago)
Type: suspicious_network_activity
Risk: 100
Events: 134
Evidence:
- Persistent suspicious network a ...
show more
Type: suspicious_network_activity
Risk: 100
Events: 134
Evidence:
- Persistent suspicious network activity detected
- Repeated hostile operational behavior observed
- Multi-event operational persistence identified
- Threat escalation behavior observed
show less
Port Scan
Hacking
🇵🇱
Budyn
2026-09-06 23:25:28
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: s3.goblinpot.store | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:15:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:f298:6:a044::f77:bdc9 (gotgrace.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:15:14.692503 2026] [security2:error] [pid 6955:tid 6955] [client 2607:f298:6:a044::f77:bdc9:58124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kbalan.com"] [uri "/wp-config.php.bak"] [unique_id "ap27wkLp5xExFiYsiK4qWQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-09-06 17:15:41
(1 day ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot