🇵🇱
sefinek.net
2026-09-15 06:22:35
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
LRob
2026-09-15 06:18:31
(4 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /api/session/properties | 2026-09-15 06:18 UTC
show less
Bad Web Bot
🇮🇹
VHosting
2026-09-15 05:20:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
TheDjRider
2026-09-15 04:54:42
(5 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-15T04:54:39.579105713Z. Context: http_status=200
show less
Web App Attack
🇳🇱
Alt255
2026-09-15 04:22:30
(6 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a01:4f9:c014:ea31::1 - - [15/Sep/2026:06:22:30 +0200] "GET /wp-config.php.bak HTTP/1.1" 301 5730 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
0x44
2026-09-15 04:16:37
(6 hours ago)
Abusive host detected - Web probing for vulnerabilities
Web App Attack
🇩🇪
Blexyel
2026-09-15 03:53:14
(6 hours ago)
2a01:4f9:c014:ea31::1 - - [15/Sep/2026:05:53:13 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozi ...
show more
2a01:4f9:c014:ea31::1 - - [15/Sep/2026:05:53:13 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇫🇮
as211431.net
2026-09-15 02:23:32
(8 hours ago)
Triggered Cloudflare WAF (linkMaze) from FI.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from FI.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇵🇱
Budyn
2026-09-15 00:35:31
(10 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 23:57:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:56:53.435273 2026] [security2:error] [pid 12069:tid 12069] [client 2a01:4f9:c014:ea31::1:42362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angeltarrac.com"] [uri "/.git/config"] [unique_id "aqiJxfGf3Bp1pMBlbCnTVgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 23:41:32
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:41:26.865407 2026] [security2:error] [pid 8427:tid 8427] [client 2a01:4f9:c014:ea31::1:34148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aroilcontrolsystem.com"] [uri "/.env.txt"] [unique_id "aqiGJqb8OdrXkJ4eNaic1gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 22:41:32
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 18:41:25.140097 2026] [security2:error] [pid 8734:tid 8734] [client 2a01:4f9:c014:ea31::1:34894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aquatech-ind.com"] [uri "/.git/HEAD"] [unique_id "aqh4FeZnaRwBElyXbJLuOAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 21:53:50
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:53:45.404589 2026] [security2:error] [pid 25182:tid 25182] [client 2a01:4f9:c014:ea31::1:54758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazeconsultants.org"] [uri "/.git/config"] [unique_id "aqhs6QXswoZNNFW6K_Gt0QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 21:28:10
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:4f9:c014:ea31::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 17:28:04.180669 2026] [security2:error] [pid 18148:tid 18148] [client 2a01:4f9:c014:ea31::1:60010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alosi.us"] [uri "/.git/config"] [unique_id "aqhm5LDvRIk_QtxVvRaibwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-14 21:20:42
(13 hours ago)
2a01:4f9:c014:ea31::1 - - [14/Sep/2026:23:20:41 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data? ...
show more
2a01:4f9:c014:ea31::1 - - [14/Sep/2026:23:20:41 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 4622 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 2a01:4f9:c014:ea31::1 - - [14/Sep/2026:23:20:42 +0200] "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 4440 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 2a01:4f9:c014:ea31::1 - - [14/Sep/2026:23:20:42 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 4621 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Brute-Force