๐ฑ๐ป
garmtech.com
2026-05-08 12:35:26
(4 weeks ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-35.104.207.35.181.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 15-35.104.207.35.181.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
mnsf
2026-03-15 14:05:30
(2 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-10 22:59:11
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-10
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-10 03:31:19
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 22:31:10.546134 2026] [security2:error] [pid 20538:tid 20538] [client 104.207.35.181:41967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirt.us"] [uri "/.env.save"] [unique_id "aYqmfg1RMQkPIpCc5ogeZQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:47:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:47:20.809172 2026] [security2:error] [pid 6205:tid 6205] [client 104.207.35.181:10905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madisonjazzorchestra.com"] [uri "/app/.git/config"] [unique_id "aYqcOIZNPbkFgbE0fwu9HgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-10 02:31:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 21:31:16.312405 2026] [security2:error] [pid 726:tid 726] [client 104.207.35.181:28169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinaffanchufoods.com"] [uri "/.env.save"] [unique_id "aYqYdIw99vVAOhGbxv4FmwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 23:19:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 18:19:36.501418 2026] [security2:error] [pid 15271:tid 15271] [client 104.207.35.181:32301] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keeran.org"] [uri "/api/.env"] [unique_id "aYpriPK5ky5bHMHrVBbffgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 19:29:23
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 14:29:17.521541 2026] [security2:error] [pid 15597:tid 15597] [client 104.207.35.181:27835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "holtzheimer.net"] [uri "/backend/.env"] [unique_id "aYo1jYw0pQ0Lxs1v5Kj0FAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 20:52:39
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.35.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 15:52:32.444531 2025] [security2:error] [pid 22290:tid 22290] [client 104.207.35.181:55133] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||limpiezadevidriosyoficinas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "limpiezadevidriosyoficinas.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aRo5kEZJsGtN8VZww8f83wAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
techboy117
2025-11-14 00:26:07
(6 months ago)
Blocking due to password spraying.
Brute-Force
Anonymous
2025-11-05 13:14:58
(7 months ago)
wordpress-trap
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-10-31 07:08:54
(7 months ago)
WP Admin Scan Activities
Web App Attack
Anonymous
2025-10-28 14:18:33
(7 months ago)
wordpress-trap
Web App Attack
Anonymous
2025-10-28 00:40:06
(7 months ago)
wordpress-trap
Web App Attack
๐ต๐ฑ
sefinek.net
2025-10-20 17:09:01
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot