๐ฉ๐ช
kkeyser
2026-05-04 15:20:12
(3 months ago)
\x03\x00\x00\x13\x0E\xE0\x00\x00\x00\x00\x00\x01\x00\x08\x00\x03\x00\x00\x00
Web App Attack
๐ท๐บ
Reaper
2026-04-27 22:38:57
(3 months ago)
SSH abuse or brute-force attack from 98.159.226.68
Brute-Force
SSH
๐ท๐บ
Hobby Bob
2026-04-27 22:30:35
(3 months ago)
Apr 28 01:30:35 server dovecot: pop3-login: Disconnected: Connection closed (no auth attempts in 1 s ...
show more
Apr 28 01:30:35 server dovecot: pop3-login: Disconnected: Connection closed (no auth attempts in 1 secs): user=, rip=98.159.226.68, lip=X.X.X.X session=
show less
Port Scan
Hacking
๐ท๐บ
webserfer
2026-04-27 22:13:36
(3 months ago)
[f2b] honeypot [W1:1:?]
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-15 16:30:16
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 12:30:09.302581 2026] [security2:error] [pid 6473:tid 6473] [client 98.159.226.68:24167] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jussetcotradinglimited.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jussetcotradinglimited.co"] [uri "/bak/dump.sql"] [unique_id "abbekbzvH4b96jGBubJCJwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-03-14 23:33:39
(5 months ago)
/restore/public_html.gz
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 19:24:51
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 15:24:41.788108 2026] [security2:error] [pid 18923:tid 18923] [client 98.159.226.68:35845] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lundtrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lundtrading.com"] [uri "/old/sql.sql"] [unique_id "abW1-XFIZJYTF5gNllvZbAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-03-13 17:17:08
(5 months ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
๐ณ๐ฟ
Tripwire
2026-03-13 05:27:05
(5 months ago)
Scanning for exploits - /backup/www.gz
Web App Attack
๐ฌ๐ง
Axel
2026-03-09 11:29:33
(5 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /backup/sftp- ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /backup/sftp-config.json Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-03-04 13:07:53
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 08:07:48.263897 2026] [security2:error] [pid 4270:tid 4270] [client 98.159.226.68:43201] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/restore/backup.sql"] [unique_id "aagupOCDnvpqfbkugSb0qQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-03-04 12:35:16
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /backup.sql.zip
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Penny Packer
2026-03-04 05:45:05
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 19:29:44
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 14:29:36.508447 2026] [security2:error] [pid 602:tid 602] [client 98.159.226.68:31173] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mindtoken.app|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mindtoken.app"] [uri "/www.sql"] [unique_id "aaNCIJjS2B5GzLTLNhbd3QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-02-28 08:32:55
(5 months ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||ipvi.network|F|2 Phase: 2 Severity: CRITICAL URI: /backup/sql.sql Server: UK-01
show less
Web App Attack
Hacking
SQL Injection