๐จ๐ญ
ca
2026-07-28 20:38:04
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ซ๐ท
Octopuce
2026-07-27 14:55:01
(1 day ago)
Aggressive web search of vulnerable pages: /insc.php /classwithtostring.php /txets.php /wp-content/t ...
show more
Aggressive web search of vulnerable pages: /insc.php /classwithtostring.php /txets.php /wp-content/themes/txets.php /wp-admin/txets.php /wp-inc ...
show less
Web App Attack
Anonymous
2026-07-27 13:06:18
(1 day ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (32/60 min)'; Requests=32
Port Scan
๐บ๐ธ
RamSet
2026-07-27 10:50:38
(2 days ago)
[pit] HTTP-Probe on port 443 (via domain). 24 distinct paths probed in 14s. Sustained 24 req/min, 24 ...
show more
[pit] HTTP-Probe on port 443 (via domain). 24 distinct paths probed in 14s. Sustained 24 req/min, 24 nonexistent paths (404), scanner-tool user-agent. Paths: //zwso.php, /abcd.php, /akcc.php, /bolt.php, /cjfuns.php, /classwithtostring.php, /cord.php, /dex.php, /goods.php, /insc.php, /ioxi-o.php, /lufix.php, /shelp.php, /style.php, /txets.php, /wp-admin/admin-ajax.php, /wp-admin/css/index.php, /wp-admin/txets.php, /wp-content/index.php, /wp-content/plugins/hellopress/wp_mna.php, /wp-content/plugins/index.php, /wp-content/themes/txets.php, /wp-editor.php, /wp-includes/txets.php
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-03-17 09:11:18
(4 months ago)
Aggressive web search of vulnerable pages: /cgi-bin/cgi-bin/ /wp-content/ID3/img/img/block/wp/ /them ...
show more
Aggressive web search of vulnerable pages: /cgi-bin/cgi-bin/ /wp-content/ID3/img/img/block/wp/ /themes/zMousse/ /wp-includes/theme-compat/wp/ / ...
show less
Web App Attack
๐บ๐ธ
mashamal
2026-03-16 09:40:38
(4 months ago)
Vulnerability Probe
...
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-03-14 16:49:59
(4 months ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 22:04:32
(4 months ago)
(mod_security) mod_security (id:240000) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 18:04:24.493107 2026] [security2:error] [pid 26746:tid 26796] [client 45.89.242.147:64695] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||perspectivedesigninc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "perspectivedesigninc.com"] [uri "/images/stories/themes.php"] [unique_id "abSJ6Fi_2VNI6xJG8WduvwAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-03-12 23:55:25
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-24 00:24:22
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 19:24:15.758591 2026] [security2:error] [pid 11936:tid 11936] [client 45.89.242.147:36377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indyham.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indyham.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aZzvr1EEeg3-SsxVg-SUFgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-02-10 20:41:40
(5 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Penny Packer
2026-02-08 00:53:45
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
Penny Packer
2026-01-05 20:29:22
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-04 06:43:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 01:43:22.322834 2026] [security2:error] [pid 2738640:tid 2738661] [client 45.89.242.147:54283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluetigertees.com"] [uri "/old/sftp-config.json"] [unique_id "aVoMCh-a7jFz1TMKnKmhVwAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-16 06:14:52
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.89.242.147 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 16 01:14:45.324150 2025] [security2:error] [pid 24690:tid 24690] [client 45.89.242.147:37683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desdier.com"] [uri "/.env"] [unique_id "aUD41XHKAXPmFTFJRKIkMwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack