๐ฉ๐ช
Reinhard
2026-05-30 08:28:07
(1 week ago)
Parameter or path manipulation, hacking. /db.sql
Hacking
๐ฆ๐บ
MAGIC
2026-05-20 00:08:08
(2 weeks ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ช๐ธ
librebit
2026-05-17 04:13:10
(3 weeks ago)
Brute force
Brute-Force
Anonymous
2026-05-13 21:04:31
(3 weeks ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-22 09:54:53
(3 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 15:33:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 10 10:33:52.191329 2026] [security2:error] [pid 27876:tid 27876] [client 65.111.7.44:34291] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10mostwantedfugitives.net"] [uri "/api/.env"] [unique_id "aYtP4IFp_PIA5M7CDRl5TAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 03:32:20
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:32:12.786911 2026] [security2:error] [pid 21332:tid 21332] [client 65.111.7.44:25167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirt.us"] [uri "/new/.git/config"] [unique_id "aYqmvDH01PVfM__9vk1e5gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 00:45:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 19:45:24.535192 2026] [security2:error] [pid 31487:tid 31487] [client 65.111.7.44:54399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keymarketmedia.com"] [uri "/.git/config"] [unique_id "aYp_pMG2lDuoRbR3Ge07dgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:03:14
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:03:01.252064 2026] [security2:error] [pid 10561:tid 10561] [client 65.111.7.44:41515] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howwegothere.info"] [uri "/app/.env"] [unique_id "aYpnpVxGEPQtbjztzqTBLwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-01-20 17:51:25
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ipblock.com
2026-01-12 14:32:00
(4 months ago)
IPBlock protected site ID [4055-d][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-01-03 00:07:43
(5 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-07.65.111.7.44.web-spammers ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 02-07.65.111.7.44.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฉ๐ช
LRob.fr
2025-12-03 00:04:54
(6 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 20:06:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 15:06:25.807258 2025] [security2:error] [pid 27825:tid 27825] [client 65.111.7.44:31363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fairytaleinvitations.com"] [uri "/.env"] [unique_id "aS9GwQ8KCN1xNQPsWQ8hxQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 15:50:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.7.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 10:50:51.959592 2025] [security2:error] [pid 28622:tid 28622] [client 65.111.7.44:36923] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stbensbluesfest.com"] [uri "/.svn/wc.db"] [unique_id "aS8K27b26uVvIi8pOiwkKgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack