Anonymous
2025-09-13 01:37:52
(8 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ต๐ฑ
ketovoila.pl
2025-09-11 21:54:00
(9 months ago)
Automated malicious traffic against WordPress site. Multiple unauthorized requests targeting honeypo ...
show more
Automated malicious traffic against WordPress site. Multiple unauthorized requests targeting honeypot endpoints. Behavior consistent with botnet reconnaissance and exploitation attempts.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 07:14:11
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 03:14:08.452829 2025] [security2:error] [pid 20297:tid 20297] [client 154.94.15.26:26491] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dealandriaproperties.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dealandriaproperties.com"] [uri "/s3cmd.ini"] [unique_id "aMElQEMMKpT7t2AkjSGGOAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 23:20:24
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 19:20:20.112756 2025] [security2:error] [pid 10669:tid 10669] [client 154.94.15.26:46559] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.crazypencil.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.crazypencil.com"] [uri "/s3cmd.ini"] [unique_id "aLzBtEXFV0ziUm4LBphACAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-06 20:56:31
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 16:56:24.751304 2025] [security2:error] [pid 22706:tid 22706] [client 154.94.15.26:38625] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.daveewalker.bz|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.daveewalker.bz"] [uri "/s3cmd.ini"] [unique_id "aLyf-BWMaNF60IVg50Sb9QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-17 07:36:52
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-08-16 06:39:32
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฆ๐บ
oncord
2025-06-13 23:04:35
(11 months ago)
Form spam
Web Spam
Anonymous
2025-05-05 13:56:00
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ต๐ฑ
sefinek.net
2025-05-04 10:00:26
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from ES.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-05-03 13:28:26
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-11 01:48:01
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-04-05 10:57:45
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-04-04 23:30:30
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 154.94.15.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 04 19:30:25.696554 2025] [security2:error] [pid 3054767:tid 3054767] [client 154.94.15.26:53043] [client 154.94.15.26] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||belindalloyd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "belindalloyd.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z_BrkVS68CryAb_YhkENEAAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
syokadmin
2024-11-15 02:43:23
(1 year ago)
(cpanel) Failed cPanel login from 154.94.15.26 (ES/Spain/-): 1 in the last 3600 secs
Brute-Force
Web App Attack