๐ซ๐ท
dynamix
2026-07-25 20:31:26
(19 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
Octopuce
2026-07-25 18:58:15
(20 hours ago)
Aggressive web search of vulnerable pages: /.well-known/ /.well-known/pki-validation/ /vendor/phpuni ...
show more
Aggressive web search of vulnerable pages: /.well-known/ /.well-known/pki-validation/ /vendor/phpunit/phpunit/src/Util/PHP/ /wp-content/uploads ...
show less
Web App Attack
๐น๐ท
neron
2026-07-25 08:27:07
(1 day ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐จ๐ญ
zynex
2026-07-15 18:47:16
(1 week ago)
URL Probing: /test/wp-includes/wlwmanifest.xml
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-05 16:02:42
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
dynamix
2026-07-05 14:00:48
(3 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-04 12:25:32
(3 weeks ago)
(y4) Failed scan -byebye- from 91.217.249.35 (DE/Germany/-): (CF_ENABLE)
Hacking
๐ฌ๐ท
setupgr
2026-06-24 12:29:39
(1 month ago)
(mod_security) mod_security (id:1000001) triggered by 91.217.249.35 (DE/Germany/Hesse/Frankfurt am M ...
show more
(mod_security) mod_security (id:1000001) triggered by 91.217.249.35 (DE/Germany/Hesse/Frankfurt am Main/-/[AS206092 SECFIREWALLAS]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Wed Jun 24 15:29:38.026499 2026] [security2:error] [pid 2470:tid 2575] [client 91.217.249.35:48347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/error.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "93"] [id "1000001"] [msg "Bad file blocked: /templates/cassiopeia/error.php"] [severity "CRITICAL"] [tag "security"] [hostname "pankoskal.gr"] [uri "/templates/cassiopeia/error.php"] [unique_id "ajvNsttqdXtSkN1ATUzjVQAAAQc"]
show less
Port Scan
Anonymous
2026-06-24 07:53:57
(1 month ago)
[Wed Jun 24 09:53:53.345436 2026] [proxy_fcgi:error] [pid 2422:tid 2476] [client 91.217.249.35:23091 ...
show more
[Wed Jun 24 09:53:53.345436 2026] [proxy_fcgi:error] [pid 2422:tid 2476] [client 91.217.249.35:23091] AH01071: Got error 'Primary script unknown', referer: http://akcurate.de/chosen.php
[Wed Jun 24 09:53:53.839784 2026] [proxy_fcgi:error] [pid 2422:tid 2479] [client 91.217.249.35:23091] AH01071: Got error 'Primary script unknown', referer: http://akcurate.de/bypass.php
[Wed Jun 24 09:53:54.247110 2026] [proxy_fcgi:error] [pid 2422:tid 2474] [client 91.217.249.35:23091] AH01071: Got error 'Primary script unknown', referer: http://akcurate.de/config.php
[Wed Jun 24 09:53:54.750966 2026] [proxy_fcgi:error] [pid 2422:tid 2466] [client 91.217.249.35:23091] AH01071: Got error 'Primary script unknown', referer: http://akcurate.de/themes.php
[Wed Jun 24 09:53:55.629888 2026] [proxy_fcgi:error] [pid 2422:tid 2471] [client 91.217.249.35:23091] AH01071: Got error 'Primary script unknown', referer: http://akcurate.de/admin.php
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-23 02:29:12
(1 month ago)
91.217.249.35 - - [23/Jun/2026:04:28:59 +0200] "POST /xmlrpc.php HTTP/1.1" 302 7892 "-" "Mozilla/5.0 ...
show more
91.217.249.35 - - [23/Jun/2026:04:28:59 +0200] "POST /xmlrpc.php HTTP/1.1" 302 7892 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
91.217.249.35 - - [23/Jun/2026:04:29:00 +0200] "POST /xmlrpc.php HTTP/1.1" 302 839 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:121.0) Gecko/20100101 Firefox/121.0"
91.217.249.35 - - [23/Jun/2026:04:29:01 +0200] "POST /xmlrpc.php HTTP/1.1" 302 839 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
91.217.249.35 - - [23/Jun/2026:04:29:02 +0200] "POST /xmlrpc.php HTTP/1.1" 302 839 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
91.217.249.35 - - [23/Jun/2026:04:29:03 +0200] "POST /xmlrpc.php HTTP/1.1" 302 839 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
91.217.249.35 - - [23/Jun/2026:04:29:04 +0200] "POST /xmlrpc.php HTTP/1.1" 302 839 "-" "Mozil
...
show less
Brute-Force
๐ซ๐ท
ELYAZ
2026-06-16 14:00:04
(1 month ago)
(y4) Failed scan -byebye- from 91.217.249.35 (DE/Germany/-): (CF_ENABLE)
Hacking
๐ณ๐ฑ
Savvii
2026-06-15 11:47:28
(1 month ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-15 02:29:40
(1 month ago)
91.217.249.35 - - [15/Jun/2026:05:29:39 +0300] "GET /wp-includes/Requests/ HTTP/1.1" 404 706 "-" "Mo ...
show more
91.217.249.35 - - [15/Jun/2026:05:29:39 +0300] "GET /wp-includes/Requests/ HTTP/1.1" 404 706 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
91.217.249.35 - - [15/Jun/2026:05:29:39 +0300] "GET /wp-includes/ID3/ HTTP/1.1" 404 706 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-15 02:24:15
(1 month ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ฎ
as211431.net
2026-06-14 01:08:12
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /dropdown.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot