๐ฉ๐ช
0x44
2026-08-02 02:01:44
(15 minutes ago)
Abusive host detected - Web probing for vulnerabilities
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 23:58:34
(2 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 19:58:27.074756 2026] [security2:error] [pid 921523:tid 921523] [client 2a04:c300:1000::302:33100] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||dawnmazur.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "dawnmazur.com"] [uri "/"] [unique_id "am6II9LbLGQ8wjf95YrzfAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-01 21:15:45
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-2021-41773
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 19:35:32
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:949110) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 15:35:28.046253 2026] [security2:error] [pid 2311054:tid 2311054] [client 2a04:c300:1000::302:58238] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.maricotippett.com"] [uri "/"] [unique_id "am5KgMSIYzc2IGxXX-irEwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marco711
2026-08-01 17:36:00
(8 hours ago)
port/URL scanning
Port Scan
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 15:48:32
(10 hours ago)
CrowdSec: crowdsecurity/http-cve-2021-41773 | req: /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh | UA: -
Web App Attack
๐จ๐ฆ
1gz
2026-08-01 15:24:54
(10 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /_next
UA: TLM-Audit-Scanner/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-01 15:03:01
(11 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:02:55.055682 2026] [security2:error] [pid 11885:tid 11885] [client 2a04:c300:1000::302:55804] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||diuana.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "diuana.com"] [uri "/"] [unique_id "am4Kn6g68BloVLvcNGUCcAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-01 13:48:35
(12 hours ago)
134 requests with url.path /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
maxpower
2026-08-01 13:35:54
(12 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 2a04:c300:1000::302 (US/United States/-): 1 in the last 3600 s ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 2a04:c300:1000::302 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a04:c300:1000::302 - - [01/Aug/2026:15:35:47 +0200] "POST /?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 301 362 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "2a04:c300:1000::302" host=ilgiardinodeiciliegi.villapardi.it
show less
Port Scan
๐ฉ๐ช
maxpower
2026-08-01 11:10:45
(15 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a04:c300:1000::302 (US/United States/-) ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a04:c300:1000::302 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a04:c300:1000::302 - - [01/Aug/2026:13:10:42 +0200] "POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 15580 "-" "Mozilla/5.0 (compatible; ClaudeBot/1.0; [email protected] )" "-" host=mail.lucadipa.com
show less
Port Scan
๐ฆ๐บ
aranguren.org
2026-08-01 11:07:26
(15 hours ago)
2a04:c300:1000::302 - - [01/Aug/2026:21:07:17 +1000] "GET /pagead/js/adsbygoogle_direct.js HTTP/1.1" ...
show more
2a04:c300:1000::302 - - [01/Aug/2026:21:07:17 +1000] "GET /pagead/js/adsbygoogle_direct.js HTTP/1.1" 404 993 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Mobile/15E148 Safari/604.1"
2a04:c300:1000::302 - - [01/Aug/2026:21:07:18 +1000] "GET /pagead/js/adsbygoogle.js HTTP/1.1" 404 993 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Mobile/15E148 Safari/604.1"
2a04:c300:1000::302 - - [01/Aug/2026:21:07:18 +1000] "GET /tag/js/gpt.js HTTP/1.1" 404 993 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15"
2a04:c300:1000::302 - - [01/Aug/2026:21:07:22 +1000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 926 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
2a04:c300:1000::302 - - [01/Aug/2026:21:07:24 +1000] "POST /vendo
...
show less
Bad Web Bot
๐ต๐ฑ
mscode.pl
2026-08-01 09:08:47
(17 hours ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 22295 (Advin Services L ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
ASN: 22295 (Advin Services LLC)
Protocol: HTTP/1.1 (POST method)
Zone: r2zsz.msikorski.me
Endpoint: /
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
๐ฉ๐ช
4server
2026-08-01 07:42:39
(18 hours ago)
[SatAug0109:42:36.9856192026][security2:error][pid1242735:tid1242754][client2a04:c300:1000::302:0]Mo ...
show more
[SatAug0109:42:36.9856192026][security2:error][pid1242735:tid1242754][client2a04:c300:1000::302:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"=\(\?:ogg\|tls\|ssl\|gopher\|file\|data\|php\|zlib\|zip\|glob\|s3\|phar\|rar\|s\(\?:sh2\?\|cp\)\|dict\|expect\|\(\?:ht\|f\)tps\?\)://\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"522\"][id\"340165\"][rev\"292\"][msg\"Atomicorp.comWAFRules:UniencodedpossibleRemoteFileInjectionattemptinURI\(AE\)\"][data\"/\?\\\\xaddallow_url_include=1\\\\xaddauto_prepend_file=php://input\"][severity\"CRITICAL\"][hostname\"autodiscover.buletti-panettoni.ch\"][uri\"/\"][unique_id\"am2jbGfTq8YirxmDzBwojAAAAAg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 05:23:44
(20 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:218420) triggered by 2a04:c300:1000::302 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 01:23:38.161406 2026] [security2:error] [pid 12477:tid 12477] [client 2a04:c300:1000::302:7860] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||mail.mangamaster.org|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "mail.mangamaster.org"] [uri "/"] [unique_id "am2C2m3dVXVJid0_Sw5w7QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack