๐บ๐ธ
Axel
2026-06-13 11:10:35
(1 week ago)
Blocked by UFW on MVI [54741/tcp] | SPT: 8081 | TTL: 53 | LEN: 52 | TOS: 0x00 โข Reported by: github. ...
show more
Blocked by UFW on MVI [54741/tcp] | SPT: 8081 | TTL: 53 | LEN: 52 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ธ๐ฎ
extremevital
2026-05-31 19:50:04
(3 weeks ago)
...
Bad Web Bot
Anonymous
2026-05-28 10:00:05
(3 weeks ago)
WordPress vulnerability scanning and Lottery/prize scamming detected
Bad Web Bot
Web App Attack
Anonymous
2026-05-22 00:08:54
(1 month ago)
Unauthorized connection attempt on Port 23
Port Scan
Hacking
Exploited Host
Anonymous
2026-05-09 03:15:14
(1 month ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Anonymous
2026-04-12 23:09:21
(2 months ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-12 20:26:03
(2 months ago)
(mod_security) mod_security (id:217210) triggered by 45.250.252.93 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 45.250.252.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 16:25:54.385302 2026] [security2:error] [pid 2139948:tid 2139948] [client 45.250.252.93:45118] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||ca33borns.shop|F|4"] [data "GET http://ca33borns.shop HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ca33borns.shop"] [uri "/"] [unique_id "adv_0hJw8TKmc9CZj-KMQgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
Sawasdee
2026-04-09 22:34:21
(2 months ago)
Port Scan
...
Port Scan
๐ซ๐ท
geot
2025-12-12 12:26:37
(6 months ago)
POST / HTTP/1.1
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2025-12-12 00:14:29
(6 months ago)
Aggressive web scan
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2025-12-11 19:05:16
(6 months ago)
Aggressive web scan
Web App Attack
๐ช๐ธ
el-brujo
2025-12-11 13:23:07
(6 months ago)
11/Dec/2025:14:23:07.182262 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
11/Dec/2025:14:23:07.182262 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 45.250.252.93] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((43314*41306))) found within ARGS:0: {then:$1:__proto__:then status:resolved_model reason:-1 value:{then:$b1337} _response:{_prefix:var res=process.mainmodule.require(child_process).execsync(echo $((43314*41306))).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [
...
show less
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2025-12-11 10:33:57
(6 months ago)
Cloudflare WAF: Request Path: / Request Query: Host: whk.elhacker.net userAgent: Mozilla/5.0 (Macin ...
show more
Cloudflare WAF: Request Path: / Request Query: Host: whk.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.16; rv:85.0) Gecko/20100101 Firefox/85.0 Action: block Source: firewallManaged ASN Description: LATITUDE-SH Country: CL Method: POST Timestamp: 2025-12-11T10:33:57Z ruleId: 3fe69f2a728e40dfabd2cfb602a9ee96. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2025-12-11 06:22:33
(6 months ago)
11/Dec/2025:07:22:32.810208 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
11/Dec/2025:07:22:32.810208 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 45.250.252.93] ModSecurity: Warning. Pattern match "(?:\\\\\\\\$(?:\\\\\\\\((?:\\\\\\\\(.*\\\\\\\\)|.*)\\\\\\\\)|\\\\\\\\{.*\\\\\\\\})|[<>]\\\\\\\\(.*\\\\\\\\))" at ARGS:0. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41635*40275))) found within ARGS:0: {then:$1:__proto__:then status:resolved_model reason:-1 value:{then:$b1337} _response:{_prefix:var res=process.mainmodule.require(child_process).execsync(echo $((41635*40275))).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks:$q2 _formdata:{get:$1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attack-rce"] [
...
show less
Hacking
Web App Attack
๐ต๐ฑ
sefinek.net
2025-12-11 06:08:41
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from CL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot