๐ฎ๐น
CoreTech srl
2026-08-22 06:08:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-08-22 08:04:17,190 fail2ban.filter [1480]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-22 08:04:17,190 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.3 - 2026-08-22 08:04:17cloudlinux2 fail2ban: 2026-08-22 08:04:17,362 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.83 - 2026-08-22 08:04:17cloudlinux2 fail2ban: 2026-08-22 08:04:58,193 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 103.224.152.109 - 2026-08-22 08:04:58cloudlinux2 fail2ban: 2026-08-22 08:05:08,706 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.80 - 2026-08-22 08:05:08cloudlinux2 fail2ban: 2026-08-22 08:05:08,719 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 104.23.160.154 - 2026-08-22 08:05:08cloudlinux2 fail2ban: 2026-08-22 08:05:52,275 fail2ban.filter [1480]: INFO [recidive] Found 103.224.152.109 - 2026-08-22 08:05:52cloudlinux2 fail2ban: 2026-08-22 08:05:52,183 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 103.224.152.109 - 2026-08-22 08:05:
show less
Brute-Force
๐ฉ๐ช
4server
2026-08-22 04:29:01
(3 hours ago)
[SatAug2206:28:56.1423802026][security2:error][pid1985339:tid1985432][client104.23.160.3:0]ModSecuri ...
show more
[SatAug2206:28:56.1423802026][security2:error][pid1985339:tid1985432][client104.23.160.3:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.respiratrentino.it\"][uri\"/.git/HEAD\"][unique_id\"aokliJdxjrupF-0Me7R9UwAAANY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-22 04:16:45
(3 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 07:46:52
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 03:46:43.589149 2026] [security2:error] [pid 25369:tid 25369] [client 104.23.160.3:10465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.toppress.ca"] [uri "/.git/HEAD"] [unique_id "aogCY-UePcp7pxqPYMSmFwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 04:52:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 00:52:28.324362 2026] [security2:error] [pid 4832:tid 4832] [client 104.23.160.3:11409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fashionisland.ca"] [uri "/.git/config"] [unique_id "aofZjHwawAwL9V0d4pDGqwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-21 00:16:45
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 21:08:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 17:08:42.782539 2026] [security2:error] [pid 486:tid 486] [client 104.23.160.3:12251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.q3.evolute.io"] [uri "/.git/HEAD"] [unique_id "aods2vMl2aCrqk-FW0sSuwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 01:00:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 21:00:23.354907 2026] [security2:error] [pid 1775:tid 1775] [client 104.23.160.3:10331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bhu.rcto.us"] [uri "/.git/config"] [unique_id "aoZRp9PSmPUOj2QdN6RDDQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 21:47:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 17:47:27.804012 2026] [security2:error] [pid 31763:tid 31763] [client 104.23.160.3:13348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cbrarauco.cl"] [uri "/.git/HEAD"] [unique_id "aoYkb1Db0PAtk1Heycfb5wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-19 21:13:09
(2 days ago)
[20/Aug/2026:00:13:08 +0300] -- 104.23.160.3 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[20/Aug/2026:00:13:08 +0300] -- 104.23.160.3 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 18:20:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 14:20:27.595835 2026] [security2:error] [pid 30543:tid 30543] [client 104.23.160.3:11646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aycart.es"] [uri "/.git/HEAD"] [unique_id "aoXz6_IfXP-NlChb3MCs9AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 16:18:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 12:18:50.369810 2026] [security2:error] [pid 29557:tid 29564] [client 104.23.160.3:11661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abadie.com.uy"] [uri "/.git/HEAD"] [unique_id "aoXXak09W-tZ9j3Z6zmQAwAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2025-06-26 21:12:13
(1 year ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /login_up.php
UA: Mozilla/5.0 (compatible; wpbot/1.3; +https://forms.gle/ajBaxygz9jSR8p8G9)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
mawan
2025-06-21 13:46:06
(1 year ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ต๐ฑ
vexhost.pl
2025-06-11 15:57:28
(1 year ago)
Suspicous activity [srv-R9-1] | 2025-06-11 15:57:28 UTC
Brute-Force