Anonymous
2026-06-27 14:21:11
(2 months ago)
Web App Attack
π¦πΊ
MAGIC
2026-06-17 01:00:34
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π©πͺ
ghostwarriors
2026-06-01 20:20:05
(3 months ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-06-01 20:16:40
(3 months ago)
Fail2Ban triggered
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-05-28 14:09:19
(3 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
NL/Netherlands/-
Web App Attack
π―π΅
SentinalX by uzumaru
2026-05-28 03:26:42
(3 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: netiptv.eu:80
show less
Open Proxy
Port Scan
Anonymous
2026-05-07 03:01:17
(4 months ago)
Web App Attack
π«π·
Baking333
2026-04-03 21:55:55
(5 months ago)
[redacted] 45.130.81.21 - - [03/Apr/2026:22:55:53 +0100] "GET //wordpress/ HTTP/1.1" 301 4345 0/480 ...
show more
[redacted] 45.130.81.21 - - [03/Apr/2026:22:55:53 +0100] "GET //wordpress/ HTTP/1.1" 301 4345 0/480 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.3124.85" [redacted] 45.130.81.21 - - [03/Apr/2026:22:55:53 +0100] "GET /wordpress HTTP/1.1" 302 1559 0/89449 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36 Edg/139.0.3124.85"
show less
Bad Web Bot
Web App Attack
πΊπΈ
interbiznw.com
2026-03-31 19:40:45
(5 months ago)
wordpress-fuzzing
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-15 17:15:21
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 13:15:13.727654 2026] [security2:error] [pid 12579:tid 12579] [client 45.130.81.21:44547] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nationalenq.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nationalenq.com"] [uri "/backups/backup.sql"] [unique_id "abbpIVCvFj6bSY4WJYNfnQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
pinguin
2026-03-15 13:06:36
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from UA.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from UA.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /bak.rar
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-03-13 02:03:27
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 22:03:19.479334 2026] [security2:error] [pid 28927:tid 28927] [client 45.130.81.21:51135] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pathpa.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pathpa.org"] [uri "/backups/www.sql"] [unique_id "abNwZzDh_FE7d5-skW4mUgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅πΎ
armandosaucedo.me
2026-03-12 06:01:39
(6 months ago)
45.130.81.21 - - [12/Mar/2026:06:01:13 +0000] "GET /back/backup.sql.tar HTTP/1.1" 404 196 "-" "-"
Web App Attack
πΊπΈ
Sylvyon
2026-03-09 19:56:24
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from UA.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from UA.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: / | UA: Empty string β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-03-09 16:58:54
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 12:58:51.297899 2026] [security2:error] [pid 4872:tid 4872] [client 45.130.81.21:49173] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spectorworld.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spectorworld.com"] [uri "/restore/dump.sql"] [unique_id "aa78Sz1LQ2TT9dg6N_sAzAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack