๐ช๐ธ
librebit
2026-05-17 07:51:21
(2 weeks ago)
Brute force
Brute-Force
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
[email protected]
2026-02-15 00:03:09
(3 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-02-15T00:03:09Z
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-30 15:49:40
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 30 10:49:34.138768 2026] [security2:error] [pid 2467423:tid 2467423] [client 104.207.45.49:52211] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXzTDsIPE90H1KT0EfGASgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2025-12-29 15:19:36
(5 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-29 02:58:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 21:58:26.301011 2025] [security2:error] [pid 21323:tid 21323] [client 104.207.45.49:50801] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accentspecialties.com"] [uri "/.env.local"] [unique_id "aSphUulCTT9T9eJOh-DtlwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 21:24:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 16:24:17.116630 2025] [security2:error] [pid 32600:tid 32600] [client 104.207.45.49:55957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abacus-rose.com"] [uri "/.env.bak"] [unique_id "aSoTAW7sruaRfSCXFBipKgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:17:32
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:17:27.702239 2025] [security2:error] [pid 15817:tid 15817] [client 104.207.45.49:15899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.joepaladino.com"] [uri "/.svn/wc.db"] [unique_id "aSQip5Zjs4TIKTZDksklkwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:38:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:37:29.995668 2025] [security2:error] [pid 9351:tid 9351] [client 104.207.45.49:38713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thehomedaleinn.com"] [uri "/.svn/wc.db"] [unique_id "aSQZSSi06kQg_D_av8Rz_QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:22:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:22:53.798703 2025] [security2:error] [pid 22811:tid 22811] [client 104.207.45.49:58223] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.koolcoastalnights.com"] [uri "/.git/HEAD"] [unique_id "aSQHzahxIeUnQ5wrAOTP1gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:00:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 00:59:55.030128 2025] [security2:error] [pid 31349:tid 31349] [client 104.207.45.49:30717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.needtoorderforms.com"] [uri "/.env"] [unique_id "aSP0W8OEP9l_sN4eveuqSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:20:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.45.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:20:35.009302 2025] [security2:error] [pid 761:tid 761] [client 104.207.45.49:54511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.heron-ent.com"] [uri "/.git/HEAD"] [unique_id "aSPdE1eXFfkBPUdzwv-btwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-28 22:12:14
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
mashamal
2025-10-26 10:05:48
(7 months ago)
Vulnerability Probe
...
Web App Attack
๐ซ๐ท
mrcrassi
2025-10-18 10:34:45
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot