๐บ๐ธ
TPI-Abuse
2026-02-25 10:54:02
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 05:53:55.235158 2026] [security2:error] [pid 19278:tid 19278] [client 104.207.54.57:61797] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thevillageartcenter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thevillageartcenter.com"] [uri "/mailto:[email protected] "] [unique_id "aZ7Uw6DpVHrliPyogZ_T0wAAABA"], referer: http://thevillageartcenter.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2025-12-12 02:11:19
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-11-25 08:20:16
(6 months ago)
"GET /.aws/credentials HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:14:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:14:51.315240 2025] [security2:error] [pid 1816810:tid 1816967] [client 104.207.54.57:14015] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.culturallyyours.lamco.us"] [uri "/.svn/wc.db"] [unique_id "aSVXa5GZcKt2mCqV6A_dwgAAAlA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:13:49
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:13:36.810157 2025] [security2:error] [pid 901934:tid 901934] [client 104.207.54.57:45019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.page-wide.com"] [uri "/.env"] [unique_id "aSVJEK3AOriwLkL22lLn5gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:56:19
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:56:13.938256 2025] [security2:error] [pid 13755:tid 13800] [client 104.207.54.57:32413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.windowtailors.com"] [uri "/.git/HEAD"] [unique_id "aSU27fPKifHcHLquJ66GIwAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:15:36
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:15:30.492724 2025] [security2:error] [pid 13944:tid 13944] [client 104.207.54.57:13713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.21north.com"] [uri "/.svn/wc.db"] [unique_id "aSUtYo1Ek6r_0XjGu1OUbQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 00:31:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:31:37.184239 2025] [security2:error] [pid 28865:tid 28865] [client 104.207.54.57:16745] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nolafoodporn.com"] [uri "/.env"] [unique_id "aST46byjVb6O24TU9h3yGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:04:13
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:04:05.595100 2025] [security2:error] [pid 26847:tid 26847] [client 104.207.54.57:48365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.mike-garner.com"] [uri "/.git/HEAD"] [unique_id "aSQDZc_gnuihvwSxvzQB9wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 06:29:13
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:29:08.012969 2025] [security2:error] [pid 28452:tid 28452] [client 104.207.54.57:9489] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.americancryonics.org"] [uri "/.svn/wc.db"] [unique_id "aSP7NP37u8eCiciwr4GPYwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:52:48
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:52:36.515509 2025] [security2:error] [pid 24639:tid 24639] [client 104.207.54.57:30077] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.athletefirst.org"] [uri "/.env"] [unique_id "aSPklKiGszYG3ZI3VQaBfAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:31:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.54.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:31:00.837799 2025] [security2:error] [pid 32570:tid 32570] [client 104.207.54.57:22387] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.jeffgambill.com"] [uri "/.svn/wc.db"] [unique_id "aSPfhHDnkZeFeRmRg2HwUAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Rosh
2025-10-27 09:23:04
(7 months ago)
[10/27/25 10:23:04] SSH: authentication failure
Brute-Force
SSH
๐ฉ๐ช
ps-center
2025-10-27 04:08:27
(7 months ago)
C1-W: TCP-Scanner. Port: 22
Port Scan
๐ฑ๐ป
garmtech.com
2025-10-25 11:07:08
(7 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-07.104.207.54.57.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 14-07.104.207.54.57.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack