๐ช๐ธ
librebit
2026-08-28 15:26:47
(10 hours ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-08-27 13:27:19
(1 day ago)
Brute force
Brute-Force
๐ฉ๐ช
psauxit
2026-04-22 10:07:03
(4 months ago)
Fail2Ban - NGINX heavily bad-bot, possible vulnerability scanning and excessive crawling/scraping
Bad Web Bot
Web App Attack
Hacking
Web Spam
๐บ๐ธ
TPI-Abuse
2026-04-09 19:50:24
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.125.30 (ec2-47-128-125-30.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.125.30 (ec2-47-128-125-30.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 15:50:20.752554 2026] [security2:error] [pid 1850897:tid 1850897] [client 47.128.125.30:47776] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.elsmithpest.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.elsmithpest.com"] [uri "/[email protected] "] [unique_id "adgC_MS7Zj6uqDIxu7QUsAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-03-06 01:47:57
(5 months ago)
Brute force
Brute-Force
๐ซ๐ท
claude CALVET
2026-02-20 13:25:58
(6 months ago)
gew-Joomla User : try to access forms...
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-15 16:43:50
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.125.30 (ec2-47-128-125-30.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.125.30 (ec2-47-128-125-30.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 11:43:45.423013 2026] [security2:error] [pid 21679:tid 21679] [client 47.128.125.30:21888] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||comics.flyingdodostudio.com|F|2"] [data ".tumblr.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "comics.flyingdodostudio.com"] [uri "/ooohshiny/inkyphalangies.tumblr.com"] [unique_id "aZH3wYJJf-0Iigvfd1H42gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
claude CALVET
2026-01-19 15:08:39
(7 months ago)
gew-Joomla User : try to access forms...
Hacking
๐ฆ๐บ
MAGIC
2026-01-17 00:14:32
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-25 11:17:10
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 47.128.125.30 (ec2-47-128-125-30.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 47.128.125.30 (ec2-47-128-125-30.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 06:17:05.971488 2025] [security2:error] [pid 16120:tid 16120] [client 47.128.125.30:22602] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/rcheek.com"] [unique_id "aU0dMZemJQDuMMUnjlsI2gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-23 20:55:27
(8 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ซ๐ท
claude CALVET
2025-12-23 04:51:35
(8 months ago)
gew-Joomla User : try to access forms...
Hacking
๐จ๐ฆ
1gz
2025-12-22 22:25:43
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /kerko.php
UA: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
bigorre.org
2025-12-16 10:26:25
(8 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐จ๐ฆ
1gz
2025-12-15 06:09:17
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /lajme/kategorite-kryesore/
UA: Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; [email protected] )
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot