๐ต๐ฑ
sefinek.net
2024-09-03 22:52:58
(2 years ago)
IP 2a0b:f4c2:1::1 [DE] triggered Cloudflare WAF (firewallCustom).
Action taken: BLOCK
ASN: 60729 (TO ...
show more
IP 2a0b:f4c2:1::1 [DE] triggered Cloudflare WAF (firewallCustom).
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
Protocol: HTTP/2 (method GET)
Domain: blocklist.sefinek.net
Endpoint: /favicon.ico
Timestamp: 2024-09-03T14:11:07Z
Ray ID: 8bd653c36fe9ca8d
Rule ID: 61a9aeb040004a25a09c35e9bfb80913
User agent: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Report generated by Node-Cloudflare-WAF-AbuseIPDB (https://github.com/sefinek24/Node-Cloudflare-WAF-AbuseIPDB)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-08-29 10:33:18
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 29 06:33:10.291253 2024] [security2:error] [pid 24873:tid 24873] [client 2a0b:f4c2:1::1:11003] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.wexfordcap.com"] [uri "/.git/config"] [unique_id "ZtBOZjkxa536vA9uulE1yAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
R.G.
2024-08-27 07:51:16
(2 years ago)
(WPLOGINorWHATEVER) Get lost please 2a0b:f4c2:1::1 (Unknown): 7 in the last 900 secs; Ports: *; Dire ...
show more
(WPLOGINorWHATEVER) Get lost please 2a0b:f4c2:1::1 (Unknown): 7 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2024-08-21 18:10:46
(2 years ago)
IP 2a0b:f4c2:1::1 [DE] triggered Cloudflare WAF (firewallCustom).
Action taken: BLOCK
ASN: 60729 (TO ...
show more
IP 2a0b:f4c2:1::1 [DE] triggered Cloudflare WAF (firewallCustom).
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET)
Protocol: HTTP/2 (method GET)
Domain: blocklist.sefinek.net
Endpoint: /generated/v1/0.0.0.0/malicious/DandelionSprout-AntiMalwareHosts.fork.txt
Query: ?_=7
Timestamp: 2024-08-21T09:10:51Z
Ray ID: 8b697e0d8ab6630a
Rule ID: 61a9aeb040004a25a09c35e9bfb80913
User agent: Mozilla/5.0 (Android 12; Mobile; rv:109.0) Gecko/115.0 Firefox/115.0
Report generated by Node-Cloudflare-WAF-AbuseIPDB (https://github.com/sefinek24/Node-Cloudflare-WAF-AbuseIPDB)
show less
Bad Web Bot
๐ฉ๐ช
Admins@FBN
2024-08-19 15:05:07
(2 years ago)
FW-PortScan: Traffic Blocked srcport=45537 dstport=443
Port Scan
๐บ๐ธ
TPI-Abuse
2024-08-18 21:30:04
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 17:29:57.011811 2024] [security2:error] [pid 32760:tid 32760] [client 2a0b:f4c2:1::1:43591] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.andrewrmarshall.com"] [uri "/.git/config"] [unique_id "ZsJn1UmMa0eHGD8iNTvMbgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 07:26:28
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 03:26:20.369884 2024] [security2:error] [pid 17525:tid 17525] [client 2a0b:f4c2:1::1:35647] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.weathercarib.net"] [uri "/.git/config"] [unique_id "ZsGiHJyXdGvSYHkL_ILMuwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 04:03:09
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 00:03:00.734966 2024] [security2:error] [pid 23142:tid 23142] [client 2a0b:f4c2:1::1:49611] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.fluffmoo.org"] [uri "/.git/config"] [unique_id "ZsFydMG7TcSMExXiUmbx7gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 03:04:25
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 23:04:21.490260 2024] [security2:error] [pid 821605:tid 821605] [client 2a0b:f4c2:1::1:47833] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.deborahbein.com"] [uri "/.git/config"] [unique_id "ZsFktSad2oBZh7_f-AxBxwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 02:28:31
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 22:28:22.459196 2024] [security2:error] [pid 19310:tid 19310] [client 2a0b:f4c2:1::1:63405] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.psares.com"] [uri "/.git/config"] [unique_id "ZsFcRrmJgGzZyRcLIibcqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-18 00:48:37
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 20:48:31.894617 2024] [security2:error] [pid 6935:tid 6935] [client 2a0b:f4c2:1::1:31587] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.norbertesser.com"] [uri "/.git/config"] [unique_id "ZsFE35pFBymwYSRViMHcxgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-08-15 18:10:09
(2 years ago)
Unsollicted Connect (4 Times), to port(s): 443
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-11 08:42:51
(2 years ago)
(mod_security) mod_security (id:240000) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:240000) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 04:42:46.347023 2024] [security2:error] [pid 27371:tid 27497] [client 2a0b:f4c2:1::1:48231] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||ecothermtech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "ecothermtech.com"] [uri "/home/images/stories/evil.php"] [unique_id "Zrh5huju4fXl8ocMlignkgAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
applemooz
2024-08-10 07:47:37
(2 years ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฉ๐ช
OiledAmoeba
2024-08-09 04:25:24
(2 years ago)
2a0b:f4c2:1::1 - - [06/Aug/2024:22:57:48 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 403 ...
show more
2a0b:f4c2:1::1 - - [06/Aug/2024:22:57:48 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 403 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.551 "-"
2a0b:f4c2:1::1 - - [09/Aug/2024:06:25:22 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 200 258 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.682 "-"
2a0b:f4c2:1::1 - - [09/Aug/2024:06:25:23 +0200] "www.ruhnke.cloud" "POST //xmlrpc.php HTTP/1.1" 200 256 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36" "-" 0.631 "-"
...
show less
Brute-Force