Anonymous
2025-09-11 16:26:18
(11 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 13:11:04
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 09:10:56.635576 2025] [security2:error] [pid 29787:tid 29787] [client 154.213.194.53:51461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.drhoss.solidthought.com"] [uri "/config.php%7C/.env%7Csettings.py"] [unique_id "aMLKYJSP-R6KIL18nwzkYQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 07:53:46
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 03:53:42.399200 2025] [security2:error] [pid 7877:tid 7986] [client 154.213.194.53:15431] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.greencitymethods.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.greencitymethods.com"] [uri "/s3cmd.ini"] [unique_id "aMKABvvbVSOm6d-w5YfzzQAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-11 01:08:44
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 21:08:40.379637 2025] [security2:error] [pid 31703:tid 31703] [client 154.213.194.53:13249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yakarinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yakarinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aMIhGCZUR0pJWCg2xY7znAAAABo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 11:52:08
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 07:52:02.008246 2025] [security2:error] [pid 25892:tid 25892] [client 154.213.194.53:60793] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.celebrateadoption.taltonfamily.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.celebrateadoption.taltonfamily.com"] [uri "/s3cmd.ini"] [unique_id "aL1x4hNOqxRQTXlLgGisKAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2025-09-07 04:15:47
(1 year ago)
2 attack(s) detected since 2025-09-07T04:03:39.293Z, such as these: {"event":"nginx_block","ip":"154 ...
show more
2 attack(s) detected since 2025-09-07T04:03:39.293Z, such as these: {"event":"nginx_block","ip":"154.213.194.53","host":"www.adalta.info","request":"GET /.git|/.svn HTTP/1.1","user_agent":"SAMSUNG-S8000/S8000XXIF3 SHP/VPP/R5 Jasmine/1.0 Nextreaming SMM-MMS/1.2.0 profile/MIDP-2.1 configuration/CLDC-1.1 FirePHP/0.3","reason":"request:malformed","timestamp":"2025-09-07T04:03:54 00:00","logentry":"www.adalta.info 154.213.194.53 - - [07/Sep/2025:04:03:54 0000] \"GET /.git|/.svn HTTP/1.1\" 400 157 \"-\" \"SAMSUNG-S8000/S8000XXIF3 SHP/VPP/R5 Jasmine/1.0 Nextreaming SMM-MMS/1.2.0 profile/MIDP-2.1 configuration/CLDC-1.1 FirePHP/0.3\" \"-\" \"matched:request:malforโฆ Report Details: https://p4u.xyz/P53MIAQTC9H/1IP Details: https://p4u.xyz/P53MIAQTC9H/2
show less
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-01 01:17:00
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 21:16:56.727238 2025] [security2:error] [pid 10514:tid 10514] [client 154.213.194.53:26485] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ceta-arts.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ceta-arts.com"] [uri "/s3cmd.ini"] [unique_id "aLT0CKRVG8mtCFxYs4qKBgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2025-08-14 21:57:59
(1 year ago)
2025-08-14 @ 23:57:58 (CET) ~ Blocked based on risk assessment and prior abuse reports
Web App Attack
๐ฒ๐พ
syokadmin
2025-08-12 11:33:40
(1 year ago)
(cpanel) Failed cPanel login from 154.213.194.53 (FR/France/-): 1 in the last 3600 secs
Brute-Force
Web App Attack
Anonymous
2025-08-06 12:40:24
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ต๐ฑ
sefinek.net
2025-07-26 11:43:08
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-23 16:34:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.194.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 23 12:34:51.363428 2025] [security2:error] [pid 6007:tid 6007] [client 154.213.194.53:44457] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||afdfurniture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "afdfurniture.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aIEPK01TYoZvtXyc4c4GzAAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-23 15:49:01
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
nationaleventpros.com
2025-07-16 11:54:58
(1 year ago)
WordPress login attempt
Brute-Force
๐ฆ๐บ
oncord
2025-02-28 03:32:28
(1 year ago)
Form spam
Web Spam