๐บ๐ธ
TPI-Abuse
2026-07-15 06:31:03
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 02:29:14.760272 2026] [security2:error] [pid 32647:tid 32647] [client 104.23.225.140:12918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tpdtuberental.com.bonefrog.com"] [uri "/.env.production.local"] [unique_id "alcoujpLGEBbvbTD3UjQ6AAAAFU"], referer: https://www.google.com/search?q=www.tpdtuberental.com.bonefrog.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-13 04:59:17
(1 week ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-10 21:59:43
(1 week ago)
Auto-ban: >3000 req/min op 2026-07-10
Web App Attack
SSH
Hacking
Anonymous
2026-07-04 17:54:49
(2 weeks ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 16:24:34
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 12:24:29.366641 2026] [security2:error] [pid 6597:tid 6597] [client 104.23.225.140:11557] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slimlaw.com"] [uri "/.git/config"] [unique_id "akaQvUhLIEyTLrX6JOpfPQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 01:16:39
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
mawan
2026-06-23 13:55:13
(3 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 18:04:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:04:30.351131 2026] [security2:error] [pid 11317:tid 11317] [client 104.23.225.140:10384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lutrins.fritsknuf.com"] [uri "/.git/config"] [unique_id "aicELiDwBQbYxHBVhlaA-wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-06-01 20:53:34
(1 month ago)
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (POST method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from FR.
Action taken: LOG
Protocol: HTTP/2 (POST method)
Endpoint: /
UA: Mozilla/5.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
freeutka
2026-05-15 08:24:38
(2 months ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 12:43:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 08:43:03.715089 2026] [security2:error] [pid 28049:tid 28049] [client 104.23.225.140:13411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slc.com.gt"] [uri "/.env.save"] [unique_id "agMgV8WNjzZHDAg1oCaUcQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
freeutka
2026-05-05 22:56:28
(2 months ago)
WordPress brute-force login attempt on wp-login.php.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-18 18:31:54
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 104.23.225.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 14:31:46.780244 2026] [security2:error] [pid 8720:tid 8720] [client 104.23.225.140:9303] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.photoboutiqueamerica.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.photoboutiqueamerica.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "abrvksG9B4lBBtvbEfge9QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ธ
iphouse
2026-03-16 10:30:08
(4 months ago)
Failed login attempt detected by Fail2Ban in plesk-apache jail
Web App Attack
๐ฎ๐ฉ
Diskominfo Lumajang
2026-03-15 12:05:09
(4 months ago)
Security Event Detected by SOC Diskominfo Lumajang: event=alert, hits=1
Brute-Force