๐ซ๐ท
Sklurk
2026-06-17 05:04:49
(7 hours ago)
Web App Attack
Web App Attack
Anonymous
2026-06-08 21:07:27
(1 week ago)
Banned by SPAMHAUS ASN-DROP list (ASN: 200373)
DDoS Attack
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-06 01:58:01
(2 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 65.111.0.139 (US/United States/-): 1 in the la ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 65.111.0.139 (US/United States/-): 1 in the last 3600 secs (0-193)
show less
Hacking
Anonymous
2026-03-21 15:21:33
(2 months ago)
Forum/form spam
Web Spam
๐ฑ๐ป
garmtech.com
2026-03-20 07:24:05
(2 months ago)
IM360 WAF: WordPress plugin/theme auto install block
Web App Attack
๐บ๐ธ
windowsforum
2026-02-13 03:13:09
(4 months ago)
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, url, password_confirm, ...
show more
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, url, password_confirm, username=RebbecaDeB
show less
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-09 21:49:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:49:12.235651 2026] [security2:error] [pid 15449:tid 15449] [client 65.111.0.139:16633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garyrankin.com"] [uri "/site/.git/config"] [unique_id "aYpWWM-aJz9C9kjZjg2fiwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 21:22:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:22:34.668223 2026] [security2:error] [pid 1474914:tid 1474914] [client 65.111.0.139:48303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garciadomingo.com"] [uri "/.git/config"] [unique_id "aYpQGjaA6usrjA7HOG0B9wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 20:06:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 15:06:36.081023 2026] [security2:error] [pid 7911:tid 7911] [client 65.111.0.139:26031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galaxyretro.com"] [uri "/frontend/.env"] [unique_id "aYo-TL_SqIj6tIC-6NVjDgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 17:59:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 12:59:09.211792 2026] [security2:error] [pid 16402:tid 16402] [client 65.111.0.139:21535] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furball.global"] [uri "/api/.git/config"] [unique_id "aYogbeZWUFygzH9gCUbyrgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 10:37:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 05:37:55.591489 2026] [security2:error] [pid 174437:tid 174526] [client 65.111.0.139:23601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gafmboard.com"] [uri "/.env.staging"] [unique_id "aYm5A56BO_Ujr-6P95I4WwAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 07:46:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 02:46:09.446881 2026] [security2:error] [pid 32546:tid 32546] [client 65.111.0.139:57141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuzzyecho.com"] [uri "/dev/.git/config"] [unique_id "aYmQwcpEoTWGX-RMOb_pJQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 05:23:05
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.0.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 00:23:01.835358 2026] [security2:error] [pid 32553:tid 32553] [client 65.111.0.139:58921] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundingworkingcapital.com"] [uri "/.git/config"] [unique_id "aYlvNZ87oj5TDCgvJh9ptwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-01-21 10:46:00
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-01-16 14:34:05
(5 months ago)
wordpress-trap
Web App Attack