๐บ๐ธ
mccsoft.io
2026-06-11 15:50:26
(5 days ago)
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). So ...
show more
Web application attack / vulnerability scanning against our public nginx web server (TCP 80/443). Source matched a blocked-path security rule (jail nginx-444); server returned HTTP 444 (connection closed without response). TCP three-way handshake completed (full HTTP request received).
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-06-11 12:10:30
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-json/gravitysmtp/v1/config
UA: Mozilla/5.0 (Linux; Android 8.0.0; SM-G965U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-06-11 11:15:11
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
AetherFox
2026-06-11 10:06:10
(5 days ago)
AetherFox VoidGuard detected: [Thu Jun 11 10:06:10.065967 2026] [authz_core:error] [pid 25957:tid 25 ...
show more
AetherFox VoidGuard detected: [Thu Jun 11 10:06:10.065967 2026] [authz_core:error] [pid 25957:tid 25980] [client 34.162.233.233:44058] AH01630: client denied by server configuration: proxy:https://[MASKED]/wp-json/gravitysmtp/v1/tests/mock-data
[Thu Jun 11 10:06:10.100342 2026] [authz_core:error] [pid 25957:tid 26005] [client 34.162.233.233:44068] AH01630: client denied by server configuration: proxy:https://[MASKED]/wp-json/wp/v2/settings
[Thu Jun 11 10:06:10.149694 2026] [authz_core:error] [pid 25957:tid 26007] [client 34.162.233.233:44080] AH01630: client denied by server configuration: proxy:https://[MASKED]/wp-json/gravitysmtp/v1/settings
[Thu Jun 11 10:06:10.178245 2026] [authz_core:error] [pid 25957:tid 25990] [client 34.162.233.233:44082] AH01630: client denied by server configuration: proxy:https://[MASKED]/wp-json/gravitysmtp/v1/tests/mock-data
[Thu Jun 11 10:06:10.250712 2026] [authz_core:error] [pid 25957:tid 25999] [client 34.162.233.233:440
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
et-a_network
2026-06-11 02:34:19
(5 days ago)
34.162.233.233 - - [11/Jun/2026:02:34:18 +0000] "GET /wp-json/wp/v2/settings HTTP/1.1" 404 53 "-" "M ...
show more
34.162.233.233 - - [11/Jun/2026:02:34:18 +0000] "GET /wp-json/wp/v2/settings HTTP/1.1" 404 53 "-" "Mozilla/5.0 (Linux; Android 5.1.1; Coolpad 3622A Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.83 Mobile Safari/537.36" host=e-pruef.et-a.eu
34.162.233.233 - - [11/Jun/2026:02:34:18 +0000] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 53 "-" "Mozilla/5.0 (Linux; Android 4.1.2; GT-N8013) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.99 Safari/537.36" host=e-pruef.et-a.eu
34.162.233.233 - - [11/Jun/2026:02:34:18 +0000] "GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 53 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2869.0 Safari/537.36" host=e-pruef.et-a.eu
34.162.233.233 - - [11/Jun/2026:02:34:18 +0000] "GET /wp-json/gravitysmtp/v1/config HTTP/1.1" 404 53 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-10 21:32:17
(5 days ago)
Web vulnerability probing: /wp-json/gravitysmtp/v1/tests/mock-data
Web App Attack
Anonymous
2026-06-10 09:12:41
(6 days ago)
PSCSERV WPSCAN 34.162.233.233
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-06-10 06:49:10
(6 days ago)
Mutliple attempts to access forbidden web resources, HTTP code 403.
Web App Attack
Anonymous
2026-06-10 02:03:04
(6 days ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐จ๐ญ
4server
2026-06-10 01:22:39
(6 days ago)
[WedJun1003:22:37.0325292026][security2:error][pid3829268:tid3829495][client34.162.233.233:0]ModSecu ...
show more
[WedJun1003:22:37.0325292026][security2:error][pid3829268:tid3829495][client34.162.233.233:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"hosting-dominio.ch\"][uri\"/wp-json/gravitysmtp/v1/tests/mock-data\"][unique_id\"aii8XbrxLAi6Bl8TDQ_85QAAAMc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-06-10 00:15:18
(6 days ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
๐ฉ๐ช
keep_out
2026-06-09 22:06:26
(6 days ago)
nginx-444 from fail2ban
...
Web App Attack
๐ฌ๐ง
consul.to
2026-06-09 16:58:27
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 16:54:12
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 34.162.233.233 (233.233.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210831) triggered by 34.162.233.233 (233.233.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:54:09.193059 2026] [security2:error] [pid 14740:tid 14740] [client 34.162.233.233:39344] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||oceanrich.biz|F|4"] [data "grub-client"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "oceanrich.biz"] [uri "/wp-json/gravitysmtp/v1/config"] [unique_id "aihFMXAI16XtjyLzBZaqbwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Oakley
2026-06-09 15:19:32
(1 week ago)
(confirmed_bot_sig) Confirmed bot
Hacking