๐ซ๐ท
Sklurk
2026-08-10 03:39:57
(2 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-08-04 02:55:51
(3 weeks ago)
Web App Attack
Web App Attack
๐ซ๐ท
Sklurk
2026-07-07 17:19:27
(1 month ago)
Web App Attack
Web App Attack
๐ฉ๐ช
ManagedStack
2026-05-29 16:45:03
(2 months ago)
Probing access to unauthorized locations
Hacking
Exploited Host
Web App Attack
๐ซ๐ท
debaba
2026-02-09 20:52:54
(6 months ago)
[09/Feb/2026:20:52:36.780901 +0000] aYpJEy_k8zuflJIK6GJQvQAAAEE 65.111.2.219 49386 127.0.0.1 7081
[0 ...
show more
[09/Feb/2026:20:52:36.780901 +0000] aYpJEy_k8zuflJIK6GJQvQAAAEE 65.111.2.219 49386 127.0.0.1 7081
[09/Feb/2026:20:52:41.692496 +0000] aYpJGWAFpLP0OAlj
...
show less
Brute-Force
Web App Attack
๐ต๐ฑ
sefinek.net
2026-01-12 00:14:34
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
MAGIC
2025-12-12 00:30:18
(8 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2025-12-09 08:51:04
(8 months ago)
botnet
DDoS Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-12-07 23:00:51
(8 months ago)
Auto-ban: >3000 req/min op 2025-12-07
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-12-05 11:29:36
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 06:29:28.994507 2025] [security2:error] [pid 30126:tid 30126] [client 65.111.2.219:24841] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zoboz.com"] [uri "/.env"] [unique_id "aTLCGI-IRNw0Ts8HVmgrWgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-27 08:23:36
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 03:23:32.890612 2025] [security2:error] [pid 26290:tid 26290] [client 65.111.2.219:28363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fundaciondamashcc.org.ec"] [uri "/.svn/wc.db"] [unique_id "aSgKhCHr8yJJ8X7Y0trPJgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 11:14:28
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 06:14:23.630869 2025] [security2:error] [pid 6939:tid 6939] [client 65.111.2.219:30609] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ocmtx.org"] [uri "/.env"] [unique_id "aSbhD90_mB9wigFJb4dbpgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-26 08:12:10
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 03:12:06.736785 2025] [security2:error] [pid 9541:tid 9581] [client 65.111.2.219:46213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.wpe.uk.com"] [uri "/.env"] [unique_id "aSa2VmMy3HNq1n2SMlt6JQAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:50:51
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:50:44.661569 2025] [security2:error] [pid 18051:tid 18051] [client 65.111.2.219:24259] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.airei.com"] [uri "/.git/HEAD"] [unique_id "aSVRxEELONJRRH3hU68WygAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:28:22
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.2.219 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:28:18.033705 2025] [security2:error] [pid 31080:tid 31080] [client 65.111.2.219:33547] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.anneoday.com"] [uri "/.git/HEAD"] [unique_id "aSU-csWQDRjXgeNs4ZueVwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack