Дата |
Страна откуда жалоба |
Описание нарушения |
2 дн. назад |
Germany |
|
3 дн. назад |
United Kingdom of Great Britain and Northern Ireland |
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /post/38822/105213
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB |
4 дн. назад |
Netherlands |
Bot / scanning and/or hacking attempts: GET /?tag=%EC%82%BC%EC%B2%99%EC%95%84%EB%8F%84-%EC%82%AC%EB%81%, GET /wp-login.php HTTP/1.1 |
5 дн. назад |
Canada |
Excessive crawling/scraping |
9 дн. назад |
Germany |
F2B - Malicious activity detected. Too many 403. |
9 дн. назад |
Belgium |
2.278 requests from abuseipdb.com blacklisted IP (1yr11mos2wfromnow) |
11 дн. назад |
Germany |
Apache Login - Brutforcing |
11 дн. назад |
Germany |
216.73.216.31 (US/United States/-), more than 10 Apache 403 hits in the last 3600 secs; Ports: 80,443,7080,7081; Direction: in; Trigger: LF_APACHE_403; Logs: |
12 дн. назад |
Netherlands |
(apache-useragents) Failed apache-useragents trigger with match [redacted]) |
12 дн. назад |
Spain |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122) |
13 дн. назад |
Netherlands |
Excessive multi-domain requests |
14 дн. назад |
Germany |
Repeated 404 errors, blocked by Fail2ban in custom-404 jail |
15 дн. назад |
Russian Federation |
216.73.216.31 - - [17/Aug/2025:10:38:26 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
216.73.216.31 - - [17/Aug/2025:10:40:21 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "http://mga.bionet.nsc.ru/sitemap.xml" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
... |
15 дн. назад |
United States of America |
Request Overload (105) |
15 дн. назад |
Germany |
Repeated 404 errors, blocked by Fail2ban in custom-404 jail |
16 дн. назад |
Russian Federation |
216.73.216.31 - - [16/Aug/2025:06:19:31 +0700] "GET /%22 HTTP/1.1" 404 196 "http://mga.bionet.nsc.ru/%22" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
216.73.216.31 - - [16/Aug/2025:06:23:02 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
... |
17 дн. назад |
Russian Federation |
216.73.216.31 - - [15/Aug/2025:13:51:39 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "http://mga.bionet.nsc.ru/sitemap.xml" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
216.73.216.31 - - [15/Aug/2025:13:52:04 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
... |
17 дн. назад |
Germany |
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously. |
17 дн. назад |
Germany |
Repeated 404 errors, blocked by Fail2ban in custom-404 jail |
18 дн. назад |
Russian Federation |
216.73.216.31 - - [14/Aug/2025:16:57:23 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "http://mga.bionet.nsc.ru/sitemap.xml" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
216.73.216.31 - - [14/Aug/2025:16:57:30 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
... |
19 дн. назад |
Russian Federation |
216.73.216.31 - - [13/Aug/2025:19:26:14 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "http://mga.bionet.nsc.ru/sitemap.xml" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
216.73.216.31 - - [13/Aug/2025:19:53:10 +0700] "GET /sitemap.xml HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
... |
19 дн. назад |
Spain |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-122) |
20 дн. назад |
France |
Aggressive Robot or Attack DDOS |
21 дн. назад |
United States of America |
Request Overload (151) |
22 дн. назад |
United States of America |
Request Overload (117) |
23 дн. назад |
Germany |
AI Bot crawler |
23 дн. назад |
United States of America |
Request Overload (103) |
24 дн. назад |
Sweden |
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-5 |
24 дн. назад |
Serbia |
HTTP/80/443/8080 Unauthorized Probe, Hack - |
27 дн. назад |
Indonesia |
[Tue Aug 05 13:10:29.220786 2025] [security2:error] [pid 361878:tid 139996320216768] [client 216.73.216.31:46765] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "bot" at REQUEST_HEADERS:User-Agent. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "228"] [id "440000"] [msg "BAD BOT - Detected and Blocked"] [data "Matched Data: bot found within REQUEST_HEADERS:User-Agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected]) request_line = GET /robots.txt HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/robots.txt"] [unique_id "aJGgVcst1JOb74Z-ClFMwAABgQQ"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[361883] [P9S3FJifd4o] [aJGgVcst1JOb74Z-ClFMwAABgQQ] keep_alive=[1] [2025-08-05 13:10:29.220793] [R:aJGgVcst1JOb74Z-ClFMwAABgQQ] UA:'Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])'
... |
29 дн. назад |
United States of America |
(mod_security) mod_security (id:225170) triggered by 216.73.216.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 02:55:16.301504 2025] [security2:error] [pid 16318:tid 16318] [client 216.73.216.31:65105] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blogs.melton.space|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blogs.melton.space"] [uri "/thehive/wp-json/wp/v2/users/1"] [unique_id "aI8H1N6W90fc-PgR8Thr1AAAABA"] |
1 мес. назад |
United States of America |
Request Overload (102) |
1 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /post/230726/493160
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB |
1 мес. назад |
United States of America |
Threat Blocked by BeeHive from (ASN:16509) (Network:AMAZON-02) (Host:soba.dev) (Method:GET) (Protocol:HTTP/2) (Timestamp:2025-07-29T22:29:02Z) |
1 мес. назад |
United States of America |
Threat Blocked by BeeHive from (ASN:16509) (Network:AMAZON-02) (Host:soba.dev) (Method:GET) (Protocol:HTTP/2) (Timestamp:2025-07-29T18:42:48Z) |
1 мес. назад |
Czechia |
[Sat Jul 26 22:34:23.770988 2025] [authz_core:error] [pid 4375:tid 4407] [client 216.73.216.31:9353] AH01630: client denied by server configuration: /srv/theor.physics.muni.cz/www/sitemap.xml
[Sun Jul 27 08:17:14.258564 2025] [authz_core:error] [pid 798086:tid 798246] [client 216.73.216.31:45772] AH01630: client denied by server configuration: /srv/theor.physics.muni.cz/www/sitemap.xml
[Sun Jul 27 09:30:04.774749 2025] [authz_core:error] [pid 798102:tid 798247] [client 216.73.216.31:43495] AH01630: client denied by server configuration: /srv/theor.physics.muni.cz/www/sitemap.xml
... |
1 мес. назад |
Spain |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-123) |
1 мес. назад |
Argentina |
Intento de hackeo |
1 мес. назад |
Spain |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122) |
2 мес. назад |
United States of America |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-173) |
2 мес. назад |
Spain |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-122) |
2 мес. назад |
Italy |
Website Scanning / Scraping |
2 мес. назад |
United States of America |
(mod_security) mod_security (id:210730) triggered by 216.73.216.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 11 16:04:56.879870 2025] [security2:error] [pid 18303:tid 18303] [client 216.73.216.31:25643] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.glamorgirl.net|F|2"] [data ".xrco.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.glamorgirl.net"] [uri "/galleries/www.xrco.com"] [unique_id "aHFuaPk4u7FWC9rQcj-IbwAAAAg"] |
2 мес. назад |
France |
sae-88 : Bloc AI bots=>/robots.txt |
2 мес. назад |
United States of America |
Web vulnerability probing |
2 мес. назад |
United States of America |
(mod_security) mod_security (id:225170) triggered by 216.73.216.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 10 11:45:51.062297 2025] [security2:error] [pid 12126:tid 12138] [client 216.73.216.31:41869] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.switchbl8.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.switchbl8.nl"] [uri "/blog/wp-json/wp/v2/users/1"] [unique_id "aG_gL7SWBqb6NrhOC3JRYgAAAMo"] |
2 мес. назад |
Russian Federation |
HTTP/HTTPS |
2 мес. назад |
United States of America |
tow-Joomla User : try to access forms... |
2 мес. назад |
United States of America |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-173) |
2 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
(PERMBLOCK) 216.73.216.31 (US/United States/-) has had more than 4 temp blocks in the last 86400 secs |
2 мес. назад |
Spain |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-123) |
2 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
(CRAWLDELAY) Generic Bot Crawl-delay Violation 216.73.216.31 (US/United States/-): 10 in the last 3600 secs |
2 мес. назад |
United States of America |
(mod_security) mod_security (id:210730) triggered by 216.73.216.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 04 07:59:40.618167 2025] [security2:error] [pid 28431:tid 28431] [client 216.73.216.31:48312] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.noviasaltovacio.com.mx|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.noviasaltovacio.com.mx"] [uri "/contactanos/[email protected]"] [unique_id "aGfCLEUKv3zPGJ1OLVUTEwAAAA4"] |
2 мес. назад |
Germany |
Fail2Ban - NGINX heavily bad-bot, possible vulnerability scanning and excessive crawling/scraping |
2 мес. назад |
United States of America |
(mod_security) mod_security (id:210730) triggered by 216.73.216.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 04 00:38:08.057802 2025] [security2:error] [pid 25184:tid 25184] [client 216.73.216.31:34887] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.borzoi-pedigree.info|F|2"] [data ".borzois.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.borzoi-pedigree.info"] [uri "/www.borzois.com"] [unique_id "aGdasKlSsETyK7G7LRHGgwAAABw"] |
2 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
(CRAWLDELAY) Generic Bot Crawl-delay Violation 216.73.216.31 (US/United States/-): 10 in the last 3600 secs |
2 мес. назад |
Netherlands |
WAF: Scan attempt by claudebot crawler 2- wsit |
2 мес. назад |
Australia |
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth |
2 мес. назад |
Netherlands |
WAF: Scan attempt by claudebot crawler 2- srv1acc |
2 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
[30/Jun/2025:21:48:16 +0100] 1M7eF8e2gb1FZQvewFki6YZG 216.73.216.31 34828 91.212.212.13 443
[30/Jun/2025:21:50:10 +0100] fJGaWuyBhuxIXrqy3hWv1HyC 216.73.216.31 37400 91.212.212.13 443
[30/Jun/2025:21:52:21 +0100] dhrhWKjAMMIaf5vJDtllSqpI 216.73.216.31 35386 91.212.212.13 443
... |
2 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
[26/Jun/2025:11:21:01 +0100] nGBdkkIR1u2ltlkSj5sScrPg 216.73.216.31 58278 91.212.212.13 443
[26/Jun/2025:11:28:53 +0100] m8H5IsliJ8m8w9MWTFiaCsgt 216.73.216.31 32690 91.212.212.13 443
[26/Jun/2025:11:33:32 +0100] ctjecvqw7ZeLcKy49dyWXBNz 216.73.216.31 49694 91.212.212.13 443
... |
2 мес. назад |
United States of America |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-173) |
2 мес. назад |
United States of America |
Detected By Fail2ban |
2 мес. назад |
Netherlands |
WAF: Scan attempt by claudebot crawler 2- srv1acc |
2 мес. назад |
Australia |
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth |
3 мес. назад |
Australia |
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth |
3 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
[10/Jun/2025:14:41:03 +0100] I6ArAExTGZUsv2bIYnmHjtxi 216.73.216.31 31836 91.212.212.14 443
[10/Jun/2025:14:41:03 +0100] I6ArAExTGZUsv2bIYnmHjtxi 216.73.216.31 43316 91.212.212.14 443
[10/Jun/2025:14:41:03 +0100] y8M9if1l0Ne799PEQnRecIXv 216.73.216.31 31836 91.212.212.14 443
... |
3 мес. назад |
United Kingdom of Great Britain and Northern Ireland |
216.73.216.31 - - [07/Jun/2025:12:18:29 +0100] "GET / HTTP/1.0" 301 904 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected])"
... |
3 мес. назад |
United States of America |
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-173) |