🇫🇮
JimArchon72
2026-08-11 10:05:04
(2 weeks ago)
2026/08/11 10:03:03 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
🇫🇷
Sklurk
2026-08-01 01:35:11
(4 weeks ago)
Web App Attack
Web App Attack
🇫🇷
Sklurk
2026-07-31 00:59:44
(4 weeks ago)
Web App Attack
Web App Attack
🇨🇭
backslash
2026-07-08 08:21:01
(1 month ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-02 13:23:35
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 09:23:30.275134 2026] [security2:error] [pid 28280:tid 28280] [client 65.111.25.78:40275] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.horizontravelgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.horizontravelgroup.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akZmUijZkq954py1Uw2OOwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
as211431.net
2026-06-16 13:32:00
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /index.php
UA: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-05-27 18:44:29
(3 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇩🇪
Lino Project
2026-03-23 02:41:31
(5 months ago)
65.111.25.78 - - [23/Mar/2026:03:41:28 +0100] "GET /xmlrpc.php HTTP/1.1" 403 3963 "https://www.primo ...
show more
65.111.25.78 - - [23/Mar/2026:03:41:28 +0100] "GET /xmlrpc.php HTTP/1.1" 403 3963 "https://www.primobio.it/mio-account/?action=register" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
65.111.25.78 - - [23/Mar/2026:03:41:30 +0100] "GET /wp-admin/post-new.php HTTP/1.1" 403 6555 "https://www.primobio.it/mio-account/?action=register" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-02-15 23:05:44
(6 months ago)
Scanning/Probing (28)
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-02-15 12:49:12
(6 months ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
big-cloud.nl
2026-02-15 12:21:10
(6 months ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 06:48:04
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 01:48:00.278196 2026] [security2:error] [pid 6921:tid 6921] [client 65.111.25.78:19063] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "talentguard.net"] [uri "/api/.git/config"] [unique_id "aZFsIGz1z_gY-SD7SnhfpwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 05:48:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:48:36.316649 2026] [security2:error] [pid 915204:tid 915204] [client 65.111.25.78:48347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sweak.com"] [uri "/backup/.git/config"] [unique_id "aZFeNK-On2SUnHIsZzBmowAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 04:24:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:24:36.234356 2026] [security2:error] [pid 5498:tid 5498] [client 65.111.25.78:17223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stringview.com"] [uri "/backend/.env"] [unique_id "aZFKhGNuS9wvHlXqiYd0bwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-15 03:47:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.25.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:47:04.544948 2026] [security2:error] [pid 25876:tid 25876] [client 65.111.25.78:62571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sternscape.com"] [uri "/.env.save"] [unique_id "aZFBuJp4uVy5G3xb-WjJjwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack