Anonymous
2026-06-17 09:25:43
(2 days ago)
FortiWeb WAF: 42 attacks detected. Threat Score: 15600. Types: Client Management(21), GEO IP(21). Or ...
show more
FortiWeb WAF: 42 attacks detected. Threat Score: 15600. Types: Client Management(21), GEO IP(21). Origin: Singapore.
show less
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-06-16 11:47:14
(3 days ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐บ๐ธ
ChamberofCommerce.com
2026-06-15 15:10:54
(4 days ago)
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested ...
show more
Unauthorized Scraping Attempt - More then 225 Pages Requested in a 24 hour period - Total Requested Before Block:226
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-15 11:18:22
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 07:18:17.962813 2026] [security2:error] [pid 19016:tid 19016] [client 47.79.201.131:39792] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dokuzadabirdeniz.com|F|2"] [data ".koreaherald.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dokuzadabirdeniz.com"] [uri "/www.koreaherald.com"] [unique_id "ai_feRVGZ6CzqbeQWub7aQAAAAc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 09:22:48
(4 days ago)
FortiWeb WAF: 44 attacks detected. Threat Score: 16400. Types: Client Management(22), GEO IP(22). Or ...
show more
FortiWeb WAF: 44 attacks detected. Threat Score: 16400. Types: Client Management(22), GEO IP(22). Origin: Singapore.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:19:54
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:19:48.433659 2026] [security2:error] [pid 16735:tid 16735] [client 47.79.201.131:25664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.hayrun.com|F|2"] [data ".hayrun.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.hayrun.com"] [uri "/blog/img_0674/www.hayrun.com"] [unique_id "ai83FO4TM2aAO0aWKUXifgAAAAE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-14 15:04:15
(5 days ago)
[SunJun1417:04:08.2997422026][security2:error][pid2711205:tid2711567][client47.79.201.131:0]ModSecur ...
show more
[SunJun1417:04:08.2997422026][security2:error][pid2711205:tid2711567][client47.79.201.131:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?i\)\(10\\\\\\\\.\\\\\\\\d{1\,3}\\\\\\\\.\\\\\\\\d{1\,3}\\\\\\\\.\\\\\\\\d{1\,3}\|192\\\\\\\\.168\\\\\\\\.\\\\\\\\d{1\,3}\\\\\\\\.\\\\\\\\d{1\,3}\|172\\\\\\\\.\(1[6-9]\|2[0-9]\|3[0-1]\)\\\\\\\\.\\\\\\\\d{1\,3}\\\\\\\\.\\\\\\\\d{1\,3}\|fe80::\)\"atREQUEST_HEADERS:X-Forwarded-For.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"25\"][id\"990004\"][msg\"SSRFattempttoprivate/internalnetworkdetected\"][hostname\"shakary.com\"][uri\"/band.html\"][unique_id\"ai7C6M-ibL0C99SeEU3M_QAAAEE\"]\,referer:https://www.google.com/
show less
Hacking
Web App Attack
๐จ๐ฆ
1gz
2026-06-14 10:07:04
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/kultivimin-e-kanabisit-mjekesor
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
FireGuard Server
2026-06-14 00:35:06
(5 days ago)
Blocked by OPNsense firewall; 4 hits, proto=tcp, ports=443
Port Scan
Hacking
Anonymous
2026-06-13 21:23:01
(5 days ago)
Malicious activity detected
Hacking
Web App Attack
๐ซ๐ท
Sklurk
2026-06-13 17:29:22
(5 days ago)
Web App Attack
Web App Attack
Anonymous
2026-06-13 09:21:50
(6 days ago)
FortiWeb WAF: 48 attacks detected. Threat Score: 19000. Types: Client Management(24), GEO IP(24). Or ...
show more
FortiWeb WAF: 48 attacks detected. Threat Score: 19000. Types: Client Management(24), GEO IP(24). Origin: Singapore.
show less
Web App Attack
๐ซ๐ท
Sklurk
2026-06-12 16:25:44
(1 week ago)
Web App Attack
Web App Attack
๐จ๐ฆ
1gz
2026-06-12 09:20:40
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/marre-me-qira
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-12 03:12:32
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.131 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 23:12:27.790752 2026] [security2:error] [pid 13327:tid 13327] [client 47.79.201.131:36732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.instituteofscience.com|F|2"] [data ".instituteofscience.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.instituteofscience.com"] [uri "/www.InstituteOfScience.com"] [unique_id "ait5GwsdBzpcD3GeadO7aAAAABU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack