๐ซ๐ท
masterguru
2026-06-02 14:05:42
(5 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.207.49.248 (BR/Brazil/-): 1 in th ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 104.207.49.248 (BR/Brazil/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
windowsforum
2026-03-30 03:42:05
(2 months ago)
Spam bot registration: triggers=timing, js_challenge, inv_honeypot, pow_fail, username=DaniloLamb
Web Spam
Bad Web Bot
๐ฉ๐ช
Lino Project
2026-03-25 04:52:24
(2 months ago)
104.207.49.248 - - [25/Mar/2026:05:52:18 +0100] "GET /wp-admin/post-new.php HTTP/1.1" 403 6555 "http ...
show more
104.207.49.248 - - [25/Mar/2026:05:52:18 +0100] "GET /wp-admin/post-new.php HTTP/1.1" 403 6555 "https://www.primobio.it/mio-account/?action=register" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
104.207.49.248 - - [25/Mar/2026:05:52:24 +0100] "GET /wp-admin/post-new.php HTTP/1.1" 403 6555 "https://www.primobio.it/mio-account/" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 16:21:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 11:21:41.377876 2025] [security2:error] [pid 7773:tid 7773] [client 104.207.49.248:12113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mayiasteadman.com"] [uri "/.env"] [unique_id "aTmeFfEIf5pBrP6ZMbEldAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 21:32:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 16:32:49.747193 2025] [security2:error] [pid 11847:tid 11847] [client 104.207.49.248:53051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alternatievemedia.com"] [uri "/.env"] [unique_id "aTXygY_zeh6GlJw0MpImawAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 14:20:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:20:06.967495 2025] [security2:error] [pid 18853:tid 18853] [client 104.207.49.248:22823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newlife12steprecovery.org"] [uri "/.svn/wc.db"] [unique_id "aTWNFuoi8UxoHDKVDwoJJQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-12-07 04:54:23
(6 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.svn/wc.db (Rule ID: 920440) - URL file extension is restricted by policy
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 10:57:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 05:57:47.992903 2025] [security2:error] [pid 16564:tid 16564] [client 104.207.49.248:29881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrew.weigel.name"] [uri "/.svn/wc.db"] [unique_id "aTQMKz9k11dihdaw1WMtcwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 22:32:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 17:32:36.355457 2025] [security2:error] [pid 29838:tid 29838] [client 104.207.49.248:48835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierrablue.farm"] [uri "/.env"] [unique_id "aTNdhHrN9osy2NHm_8YkGQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 10:55:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 05:55:06.693577 2025] [security2:error] [pid 19347:tid 19347] [client 104.207.49.248:34453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cleanbuildingservices.com"] [uri "/.env"] [unique_id "aTK6CifGNqrtWnoLsb1PrAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 08:51:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 03:51:00.207413 2025] [security2:error] [pid 20930:tid 20930] [client 104.207.49.248:36549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janeeyreillustrated.com"] [uri "/.git/HEAD"] [unique_id "aTKc9G37_ruOk_Mk13_uPAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 01:17:57
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 20:17:54.428195 2025] [security2:error] [pid 30447:tid 30447] [client 104.207.49.248:37017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bradjohnsonqh.com"] [uri "/.git/HEAD"] [unique_id "aTIywp8W5G9sC5jrjDw0hQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-27 20:23:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.248 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 15:22:58.567192 2025] [security2:error] [pid 3268:tid 3268] [client 104.207.49.248:44573] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calogerolawfirm.com"] [uri "/.svn/wc.db"] [unique_id "aSizIvaw1swivlmz-TUn6QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2025-11-01 17:47:16
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-04-07 13:47:45
(1 year ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.04.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.04.07 is noted in report timestamp
show less
Hacking
Brute-Force