Anonymous
2025-12-30 13:20:57
(5 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2025-12-29 10:30:06
(5 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:49:34
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:49:29.927439 2025] [security2:error] [pid 16768:tid 16768] [client 104.207.58.230:14519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mooseled.com"] [uri "/.env"] [unique_id "aVIWadnFt7A42b4CLiVnRwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:17:57
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:17:51.918358 2025] [security2:error] [pid 26702:tid 26702] [client 104.207.58.230:41717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noxiousthoughts.com"] [uri "/.git/HEAD"] [unique_id "aVIO_ykBf33qX4g-wxGVLgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 03:22:52
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 22:22:45.661306 2025] [security2:error] [pid 1097997:tid 1097997] [client 104.207.58.230:14113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icoinedthewordironesty.com"] [uri "/.env"] [unique_id "aVH0BSZ0DA-hbg_XKHR2VQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:12:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:12:33.688449 2025] [security2:error] [pid 5188:tid 5188] [client 104.207.58.230:57251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alwayswetandsexy.grayhost.net"] [uri "/.svn/wc.db"] [unique_id "aSQhgU7L_ydithVoYr735AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 08:01:43
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:01:39.642554 2025] [security2:error] [pid 19318:tid 19318] [client 104.207.58.230:53629] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.partyblockwedding.com"] [uri "/.svn/wc.db"] [unique_id "aSQQ4zV0CqXRWgHMRIZjNwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2025-11-24 07:24:42
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.aws/credentials
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-24 03:55:54
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:55:49.986739 2025] [security2:error] [pid 14843:tid 14860] [client 104.207.58.230:25219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.2291106.com"] [uri "/.svn/wc.db"] [unique_id "aSPXRV0D_Mes39tIl2r1MgAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 03:35:16
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 22:34:50.886736 2025] [security2:error] [pid 24329:tid 24329] [client 104.207.58.230:56965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kistner.us"] [uri "/.env"] [unique_id "aSPSWvZgvwaEGuI7L1HEmgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 02:05:53
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 21:05:42.340437 2025] [security2:error] [pid 5946:tid 5946] [client 104.207.58.230:53781] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.geo-modal.com"] [uri "/.svn/wc.db"] [unique_id "aSO9dl2bkW8lu-iW1hfX2gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-11-19 07:13:49
(6 months ago)
WP probing for vulnerabilities
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-11-15 19:36:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.58.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 14:36:08.810485 2025] [security2:error] [pid 30517:tid 30517] [client 104.207.58.230:54271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lcbf.org.ithacalions.com"] [uri "/.env"] [unique_id "aRjWKJxAxbjhDEQmBoKxSQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-19 18:02:44
(7 months ago)
Attempted brute force login to web vpn 18 time(s); last attempt for 2025.10.19 is noted in report ti ...
show more
Attempted brute force login to web vpn 18 time(s); last attempt for 2025.10.19 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-18 18:10:47
(7 months ago)
Attempted brute force login to web vpn 18 time(s); last attempt for 2025.10.18 is noted in report ti ...
show more
Attempted brute force login to web vpn 18 time(s); last attempt for 2025.10.18 is noted in report timestamp
show less
Hacking
Brute-Force