๐จ๐ญ
YF
2026-07-25 00:08:56
(21 hours ago)
Malicious web activity confirmed โ IP previously flagged as suspicious (automated re-check, score: 5 ...
show more
Malicious web activity confirmed โ IP previously flagged as suspicious (automated re-check, score: 51%)
show less
Web App Attack
๐ฎ๐น
Progetto1
2026-07-24 18:35:03
(1 day ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-07-24 10:06:50
(1 day ago)
Blocked: Reason='Suspicious traffic score=65 (review-based detection)'; Requests=4
Hacking
๐ฉ๐ช
Vegascosmetics
2026-07-24 01:52:42
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after malicious redirect / external current ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after malicious redirect / external currentUrl probe. Evidence: Absolute external URL in currentUrl (redirector/spam probe)
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 00:51:01
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 68.67.112.61 (youbot-68-67-112-61.search.you.co ...
show more
(mod_security) mod_security (id:210730) triggered by 68.67.112.61 (youbot-68-67-112-61.search.you.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 20:50:54.041438 2026] [security2:error] [pid 3034072:tid 3034072] [client 68.67.112.61:48708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cameronsol.com|F|2"] [data ".camerongunsmith.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cameronsol.com"] [uri "/cameronsol.com/www.camerongunsmith.com"] [unique_id "amK27k-ov4uMOmAIDsdwIwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-23 23:07:23
(1 day ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
webgobe
2026-07-23 09:17:44
(2 days ago)
wew-Joomla User : try to access forms...
Hacking
Anonymous
2026-07-16 08:11:00
(1 week ago)
"Packet Flood; Triggered WAF; Persistent 404 Attempts"
DDoS Attack
Anonymous
2026-07-10 11:14:00
(2 weeks ago)
"Packet Flood; Triggered WAF; Multiple attempts to access nonexistent vulnerable php files"
DDoS Attack
๐ซ๐ท
mrcrassi
2026-07-10 02:19:00
(2 weeks ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; YouBot/1.0; +https://docs.you.com/youbot; env:prod) Chrome/142.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-04-28 19:24:42
(2 months ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฎ๐ฉ
hermawan
2026-04-28 12:49:12
(2 months ago)
04/28/2026-19:49:11.339189 [Drop] [**] [1:2100001461:0] Suricata match TLS JA4 scan Uniq Zeek no 14 ...
show more
04/28/2026-19:49:11.339189 [Drop] [**] [1:2100001461:0] Suricata match TLS JA4 scan Uniq Zeek no 1461 with hash_t13d1713h1_ab0a1bf427ad_ecd0401ec68b [**] [Classification: (null)] [Priority: 3] {TCP} 68.67.112.61:41705 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-04-26 01:08:42
(2 months ago)
04/25/2026-10:53:41.461135 [Drop] [**] [1:2100001394:0] Suricata match TLS JA4 scan Uniq Zeek no 13 ...
show more
04/25/2026-10:53:41.461135 [Drop] [**] [1:2100001394:0] Suricata match TLS JA4 scan Uniq Zeek no 1394 with hash_t13d1713h1_ab0a1bf427ad_ecd0401ec68b [**] [Classification: (null)] [Priority: 3] {TCP} 68.67.112.61:3891 -> 103.166.156.58:443
...
show less
Email Spam
Hacking
๐ฎ๐ฉ
hermawan
2026-03-28 00:14:24
(3 months ago)
[Sat Mar 28 07:14:22.034802 2026] [security2:error] [pid 172779:tid 140566872442560] [client 68.67.1 ...
show more
[Sat Mar 28 07:14:22.034802 2026] [security2:error] [pid 172779:tid 140566872442560] [client 68.67.112.61:34803] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.24.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "296"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; YouBot/1.0; +https://docs.you.com/youbot; env:prod) Chrome/142.0.0.0 Safari/537.36 request_line = GET /robots.txt HTTP/1.1"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "accdXXoJWFhE3CM1SK51vQAAAAo"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[172849] [jYzVf0rRcoU] [accdXXoJWFhE3CM1SK51vQAAAAo] keep_alive=[0] [2026-03-28 07:14:22.034813] [R:accdXXoJWFhE3CM1SK51vQAAAAo] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible;
...
show less
Web App Attack
Hacking