π«π·
GEDAL
2026-08-15 00:48:31
(1 week ago)
Fail2ban webexploits @ <hostname> : 65.111.10.233 - - [15/Aug/2026:02:48:30 +0200] "GET /wp-login.ph ...
show more
Fail2ban webexploits @ <hostname> : 65.111.10.233 - - [15/Aug/2026:02:48:30 +0200] "GET /wp-login.php HTTP/1.1" 503 190 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:124.0) Gecko/20100101 Firefox/124.0"
show less
Brute-Force
SSH
π©πͺ
findlab
2026-08-13 23:05:04
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
πͺπΈ
alferez
2026-07-26 00:13:21
(4 weeks ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack
π«π·
Sklurk
2026-07-07 15:32:04
(1 month ago)
Web App Attack
Web App Attack
π«π·
Sklurk
2026-06-23 04:04:31
(2 months ago)
Web App Attack
Web App Attack
π©πͺ
HandyTreff.de
2026-05-30 23:27:58
(2 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -31.824 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -31.824 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0
show less
Web App Attack
Bad Web Bot
π¦πΊ
MAGIC
2026-01-19 03:07:29
(7 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π΅π±
sefinek.net
2025-12-29 05:05:55
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-02 10:02:17
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 05:02:09.374555 2025] [security2:error] [pid 29072:tid 29072] [client 65.111.10.233:12947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lisaraylandscapes.com"] [uri "/.svn/wc.db"] [unique_id "aS65IU71t8Tkp5dELDy0vAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-12-02 05:15:21
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:15:14.719158 2025] [security2:error] [pid 17903:tid 17903] [client 65.111.10.233:39553] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hawaiivacations.com"] [uri "/.env"] [unique_id "aS514n25I1lOCpCuIyP8FwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 09:37:59
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:37:43.293000 2025] [security2:error] [pid 11636:tid 11636] [client 65.111.10.233:53595] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.studioarmanni.com"] [uri "/.git/HEAD"] [unique_id "aSQnZ138fMeEkKgAqdzYNgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:22:03
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:21:53.768267 2025] [security2:error] [pid 24763:tid 24763] [client 65.111.10.233:47873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.photogreetingcardsonline.com"] [uri "/.env"] [unique_id "aSQHkdLkcE6feSssgP2aBQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:37:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:37:21.301408 2025] [security2:error] [pid 4184:tid 4184] [client 65.111.10.233:10589] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andy-blakk.org"] [uri "/.svn/wc.db"] [unique_id "aSP9IQ273GA_lsBEqLmguAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 05:45:50
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:45:06.906847 2025] [security2:error] [pid 3366023:tid 3366023] [client 65.111.10.233:54721] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.newcitypark.com"] [uri "/.svn/wc.db"] [unique_id "aSPw4nkd2engYjeygfb9JQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:30:45
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.10.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:30:42.296331 2025] [security2:error] [pid 18325:tid 18333] [client 65.111.10.233:25779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.giere.us"] [uri "/.git/HEAD"] [unique_id "aSPfcribCkDUtlE56PAf1gAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack