Anonymous
2026-07-07 10:36:54
(2 weeks ago)
Port scan / connection attempts on port 8080/TCP to unused IP
Port Scan
๐ฉ๐ช
femboy.cat
2026-06-19 19:24:15
(1 month ago)
Port scan to tcp/2087 from 89.38.224.165
Brute-Force
๐ณ๐ฑ
Erik
2026-06-19 19:20:54
(1 month ago)
(cpanel) Failed cPanel login from 89.38.224.165 (RS/Serbia/Belgrade/Belgrade/-): 2 in the last 3600 ...
show more
(cpanel) Failed cPanel login from 89.38.224.165 (RS/Serbia/Belgrade/Belgrade/-): 2 in the last 3600 secs
show less
Web App Attack
๐ธ๐ฌ
drewf.ink
2026-06-19 19:20:37
(1 month ago)
[19:20] Port scanning. Port(s) scanned: TCP/2087
Port Scan
๐ฌ๐ง
pinguin
2026-03-15 19:51:51
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from RS.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from RS.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /backup.sql
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 01:14:45
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 21:14:38.008139 2026] [security2:error] [pid 32500:tid 32515] [client 89.38.224.165:48175] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nobletitles.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nobletitles.org"] [uri "/backups/www.sql"] [unique_id "abYH_rob7VaF6mTGbjlKpgAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-03-15 00:11:55
(4 months ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-03-14 12:59:08
(4 months ago)
Web App Attack (ModSecurity Block). Evidence: beanietools.dev:80 89.38.224.165 - - [14/Mar/2026:12:5 ...
show more
Web App Attack (ModSecurity Block). Evidence: beanietools.dev:80 89.38.224.165 - - [14/Mar/2026:12:59:06 +0000] HEAD /back/full_backup.zip HTTP/1.1 301 188 - -
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 22:34:20
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 18:34:12.246519 2026] [security2:error] [pid 5922:tid 5922] [client 89.38.224.165:59137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||headcount.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "headcount.dev"] [uri "/restore/www.sql"] [unique_id "abSQ5Mv5FLlDQdDuhNajewAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-13 10:00:38
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 06:00:33.156765 2026] [security2:error] [pid 23657:tid 23657] [client 89.38.224.165:44205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linnardfinancial.com"] [uri "/sftp-config.json"] [unique_id "abPgQSGRuBW788CR0rdUrwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-03-10 12:31:56
(4 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-08 21:29:53
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 17:29:45.811921 2026] [security2:error] [pid 31326:tid 31326] [client 89.38.224.165:24085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matteozacchino.dev"] [uri "/bak/sftp-config.json"] [unique_id "aa3qSVINjEEzXL5tMYskLAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 17:00:45
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 12:00:39.960355 2026] [security2:error] [pid 17250:tid 17250] [client 89.38.224.165:65419] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barnesandbrower.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barnesandbrower.com"] [uri "/backup/www.sql"] [unique_id "aaMfN4cZnnLKPW0uTDfsuQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 04:43:48
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 23:43:39.997142 2026] [security2:error] [pid 9316:tid 9316] [client 89.38.224.165:42169] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mindtoken.app|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mindtoken.app"] [uri "/backups/wallet.dat"] [unique_id "aaJye1hjJfowHKQImU6VbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-02-25 23:01:29
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack