๐บ๐ธ
TPI-Abuse
2025-09-10 08:54:37
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.203.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.203.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 04:54:32.644647 2025] [security2:error] [pid 15123:tid 15163] [client 154.213.203.83:42519] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.conservativedemocrat.aafm.us|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.conservativedemocrat.aafm.us"] [uri "/s3cmd.ini"] [unique_id "aME8yBKC5z6iwMM_0_qJegAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 06:53:44
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.203.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.203.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 02:53:38.532034 2025] [security2:error] [pid 16520:tid 16520] [client 154.213.203.83:17045] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.disneylawsuit.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.disneylawsuit.com"] [uri "/s3cmd.ini"] [unique_id "aMEgckulu9DorYfWbbCbqQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-08-02 23:11:32
(1 year ago)
HTTP1.x attacks
DDoS Attack
Anonymous
2025-07-30 16:36:43
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฎ๐น
VHosting
2025-07-16 14:20:54
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
Anonymous
2025-07-16 11:39:03
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ต๐ฑ
sefinek.net
2025-07-03 11:22:28
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //cms/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-06-30 20:11:12
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
hostseries
2025-06-13 21:09:19
(1 year ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2025-05-29 12:52:08
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
hostseries
2025-05-19 01:10:34
(1 year ago)
Trigger: LF_DISTATTACK
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-04-09 04:40:42
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.213.203.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 154.213.203.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 09 00:40:38.693228 2025] [security2:error] [pid 12063:tid 12063] [client 154.213.203.83:56597] [client 154.213.203.83] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pronio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pronio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_X6Rr7wUwGg107lz7MGQQAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-04-05 14:27:05
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-03-24 08:30:00
(1 year ago)
GET /wp-login.php HTTP/1.1
POST /xmlrpc.php HTTP/1.1
GET /wp-json/wp/v2/users HTTP/1.1
Hacking
Web App Attack
Anonymous
2025-03-23 03:21:16
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH