๐ซ๐ท
Sklurk
2026-08-08 05:27:46
(3 days ago)
Web App Attack
Web App Attack
๐จ๐ด
adalbertoreyes.org
2026-07-10 21:32:52
(1 month ago)
CategoryPortScan
Port Scan
๐ซ๐ฎ
as211431.net
2026-07-06 01:27:17
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.gitlab-ci.yml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
MatStef132
2026-07-05 23:59:27
(1 month ago)
MatShield L7: blocked on mathost.eu (automation-ua)
DDoS Attack
๐ฉ๐ช
4server
2026-07-05 15:26:35
(1 month ago)
[SunJul0517:26:32.9415602026][security2:error][pid3008654:tid3008730][client65.111.6.22:0]ModSecurit ...
show more
[SunJul0517:26:32.9415602026][security2:error][pid3008654:tid3008730][client65.111.6.22:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"essesolution.ch\"][uri\"/composer.json\"][unique_id\"akp3qB57zghwJKp5FnWn5AAAAII\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
Equity Steward
2026-07-05 07:09:04
(1 month ago)
Systematic automated scraping and endpoint enumeration against equitysteward.org. 1 offences recorde ...
show more
Systematic automated scraping and endpoint enumeration against equitysteward.org. 1 offences recorded. Trigger: Honeypot path accessed: /actuator/beans โ deliberately ignored robots.txt Disallow directive.. Canary ref: 1c298716-924.
show less
Web App Attack
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-06-16 02:25:16
(1 month ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-16 02:24:51
(1 month ago)
IM360 WAF: Apache Struts OGNL injection MV:/?debug=1&error=%24%7BT%28java.lang.Runtime%29.getRuntime ...
show more
IM360 WAF: Apache Struts OGNL injection MV:/?debug=1&error=%24%7BT%28java.lang.Runtime%29.getRuntime%28%29.exec%28%27id%27%29%7D&input=%24%7BT%28java.lang.Runtime%29.getRuntime%28%29.exec%28%27id%27%29%7D
show less
Web App Attack
Anonymous
2026-03-14 20:01:41
(4 months ago)
Forum/form spam
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-30 13:09:57
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-25 06:24:42
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:24:37.914990 2025] [security2:error] [pid 13754:tid 13770] [client 65.111.6.22:19517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.anshinholdings.com"] [uri "/.env"] [unique_id "aSVLpaITODRS1uMOGv86yQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:49:22
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:49:17.303901 2025] [security2:error] [pid 10618:tid 10726] [client 65.111.6.22:10235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elizbiz.com"] [uri "/.git/HEAD"] [unique_id "aSVDXbZN1sv0sYtnp34rMgAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:20:06
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:20:00.079447 2025] [security2:error] [pid 17231:tid 17231] [client 65.111.6.22:14359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.iclog.us"] [uri "/.env"] [unique_id "aSUucPrrIFA5rfLV5ydhaAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:51:40
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:51:32.824938 2025] [security2:error] [pid 3993:tid 3993] [client 65.111.6.22:25603] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cpking.com"] [uri "/.svn/wc.db"] [unique_id "aSUnxCPVqhbu3QYdvvJNXwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:25:29
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.6.22 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:25:25.527143 2025] [security2:error] [pid 21561:tid 21561] [client 65.111.6.22:14381] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "demo.semisysteme.com"] [uri "/.svn/wc.db"] [unique_id "aSUhpQiIIDOO6KE-7BlmFwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack