πΊπΈ
EvilTurkey
2026-08-12 13:50:09
(2 weeks ago)
Web app attack against financial institution website.
Web App Attack
Hacking
π¨π
backslash
2026-08-11 17:42:00
(2 weeks ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
π·πΊ
DZBOT
2026-06-30 03:37:46
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πͺπΈ
masterguru
2026-06-30 03:26:07
(1 month ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
π°π·
MW
2026-06-12 08:22:13
(2 months ago)
85.203.45.78 - - [12/Jun/2026:17:22:10 +0900] "GET /wpx/ HTTP/1.1" 404 4232 "http://piazza.co.kr/wpx ...
show more
85.203.45.78 - - [12/Jun/2026:17:22:10 +0900] "GET /wpx/ HTTP/1.1" 404 4232 "http://piazza.co.kr/wpx/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
85.203.45.78 - - [12/Jun/2026:17:22:11 +0900] "GET /classwithtostring.php HTTP/1.1" 404 459 "http://piazza.co.kr/classwithtostring.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
85.203.45.78 - - [12/Jun/2026:17:22:12 +0900] "GET /item.php HTTP/1.1" 404 459 "http://piazza.co.kr/item.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
show less
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-06-11 20:31:17
(2 months ago)
12.750 requests with url.path //xmlrpc.php
11.440 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
π¨π¦
Dolphi
2026-06-11 16:50:03
(2 months ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
Anonymous
2026-04-04 17:06:19
(4 months ago)
Blocked: Reason='Vulnerability probing β PHP scan detected (47/60 min)'; Requests=47
Port Scan
π«π·
centurion
2026-03-14 00:09:46
(5 months ago)
Blocked by UFW on dc00 [80/tcp]
Source port: 64361
TTL: 56
Packet length: 60
TOS: 0x00
This report ...
show more
Blocked by UFW on dc00 [80/tcp]
Source port: 64361
TTL: 56
Packet length: 60
TOS: 0x00
This report was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
π¬π§
pinguin
2026-02-28 18:55:49
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /old/website.tar
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
Penny Packer
2026-02-28 15:50:27
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
π―π΅
Valhalla
2026-02-28 15:25:33
(5 months ago)
/bak/backup.zip
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-28 11:44:27
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.45.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 06:44:23.477387 2026] [security2:error] [pid 6082:tid 6119] [client 85.203.45.78:21245] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||magazineofwallstreet.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "magazineofwallstreet.com"] [uri "/back/mysql.sql"] [unique_id "aaLVF-lE2MONl5Kc-j9lCAAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
Valhalla
2026-02-28 09:39:55
(5 months ago)
/backups/website.rar
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-24 01:03:18
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 85.203.45.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 85.203.45.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 20:03:13.259298 2026] [security2:error] [pid 15580:tid 15580] [client 85.203.45.78:21631] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matteozacchino.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matteozacchino.dev"] [uri "/bak/sql.sql"] [unique_id "aZz40fOFG8IS5YV-tW2f1QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack