🇺🇸
TPI-Abuse
2026-09-08 02:40:39
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 52.238.241.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.238.241.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:40:33.902417 2026] [security2:error] [pid 2599:tid 2599] [client 52.238.241.228:44290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indyham.com"] [uri "/wp-config.php.bak"] [unique_id "ap91ofzNpN_EBNBUt3a4fQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 01:24:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.238.241.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.238.241.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 21:24:00.932275 2026] [security2:error] [pid 7078:tid 7078] [client 52.238.241.228:44299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.modestosoftwater.net"] [uri "/wp-config.php.bak"] [unique_id "ap9jsAw4SJbW31fNSlJIEAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
mrcrassi
2026-09-07 23:35:25
(3 hours ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-json/gravitysmtp/v1/tests/mock-data
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇩🇪
pltcldvlpr
2026-09-07 23:27:42
(4 hours ago)
CMS/framework probe: 52.238.241.228 - - [08/Sep/2026:01:27:41 +0200] "GET /wp-json/gravitysmtp/v1/te ...
show more
CMS/framework probe: 52.238.241.228 - - [08/Sep/2026:01:27:41 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 94544 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" asn=8075 org="Microsoft Corporation" country=US
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:53:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.238.241.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.238.241.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:52:57.257257 2026] [security2:error] [pid 10187:tid 10187] [client 52.238.241.228:25867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adlc18.mtalame.com"] [uri "/wp-config.php.bak"] [unique_id "ap8yOfJO-pNl87tn9Q2vFAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 19:05:19
(8 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇬🇧
pinguin
2026-09-07 17:42:17
(9 hours ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇧🇪
cmbplf
2026-09-07 17:40:43
(9 hours ago)
124 requests with url.path */debug.log
124 requests with url.path *debug.log
Brute-Force
Bad Web Bot
🇧🇪
FrankNeirynck
2026-09-07 15:23:47
(12 hours ago)
aitest.ttl.be 52.238.241.228 - - [07/Sep/2026:17:23:09 +0200] "GET /wp-json/gravitysmtp/v1/tests/moc ...
show more
aitest.ttl.be 52.238.241.228 - - [07/Sep/2026:17:23:09 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 404 1317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 0.008
aitest.ttl.be 52.238.241.228 - - [07/Sep/2026:17:23:31 +0200] "GET /index.php?rest_route=/gravitysmtp/v1/tests/mock-data&page=gravitysmtp-settings HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 0.000
aitest.ttl.be 52.238.241.228 - - [07/Sep/2026:17:23:46 +0200] "GET /wp-json/gravitysmtp/v1/tests/mock-data HTTP/1.1" 404 1317 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36" 0.003
...
show less
Hacking
Web App Attack
🇦🇺
afleventoffice.com.au
2026-09-07 11:53:21
(15 hours ago)
POST /en HTTP/1.1
Web App Attack
Anonymous
2026-09-07 11:20:12
(16 hours ago)
SPARSDE WEBEXPLOIT 52.238.241.228 (52.238.241.228)
Web App Attack
🇮🇹
VHosting
2026-09-07 09:30:04
(18 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
jbcrn
2026-09-07 09:00:20
(18 hours ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack