๐ฆ๐บ
oncord
2025-09-17 00:56:21
(8 months ago)
Form spam
Web Spam
๐บ๐ธ
nowyouknow
2025-09-14 05:59:19
(8 months ago)
Phishing
Web Spam
๐บ๐ธ
TPI-Abuse
2025-09-11 09:18:27
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 11 05:18:19.927220 2025] [security2:error] [pid 25453:tid 25453] [client 156.253.170.167:22825] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gescosigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gescosigns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aMKT21KsFVzKetbf2aE6pgAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nowyouknow
2025-09-10 00:52:49
(9 months ago)
(From [email protected] ) I saw that your schaferchiropractic.com website may be missing out on ...
show more
(From [email protected] ) I saw that your schaferchiropractic.com website may be missing out on approximately a thousand visitors daily. Our AI powered traffic system is tailored to enhance your site's visibility: https://ow.ly/xHHE50WTUWn
We're offering a free trial that includes four thousand targeted visitors to show the potential benefits. After the trial, we can supply up to a quarter million targeted visitors per month. This service could greatly amplify your website's reach and traffic.
show less
Phishing
Web Spam
๐ฉ๐ช
f2_IT
2025-09-04 10:44:46
(9 months ago)
SSLVPN Login attempt (blocked type h) from 156.253.170.167
Brute-Force
๐ฆ๐บ
oncord
2025-09-02 00:45:33
(9 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-08-22 11:25:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 07:25:22.575101 2025] [security2:error] [pid 6074:tid 6074] [client 156.253.170.167:35679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.internationalseniortravel.banis-associates.com"] [uri "/config.php%7C/.env%7Csettings.py%7C/.yaml%7C/.yml"] [unique_id "aKhToglI_8Udouqm73MtiQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 11:02:46
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 07:02:39.829940 2025] [security2:error] [pid 30244:tid 30244] [client 156.253.170.167:54699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adults-biz.com"] [uri "/config.php%7C/.env%7Csettings.py%7C/.yaml%7C/.yml"] [unique_id "aKhOT2N5cT0F4YbA7Mjs5wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-22 07:51:16
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 22 03:51:09.743168 2025] [security2:error] [pid 24165:tid 24165] [client 156.253.170.167:56709] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.grupo-visalud.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.grupo-visalud.com"] [uri "/s3cmd.ini"] [unique_id "aKghbeP0KP4TXnOwTf1KnAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ธ
Smel
2025-08-22 04:52:05
(9 months ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐ต๐ฑ
sefinek.net
2025-08-14 02:38:00
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฆ๐บ
oncord
2025-08-09 08:07:08
(10 months ago)
Form spam
Web Spam
๐ฆ๐บ
oncord
2025-08-03 04:30:01
(10 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2025-08-01 13:47:13
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 156.253.170.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 01 09:47:06.607075 2025] [security2:error] [pid 9031:tid 9031] [client 156.253.170.167:30425] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coolingsprings.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coolingsprings.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aIzFWny3nObTUtoWhcQ7owAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Admins@FBN
2025-08-01 06:23:54
(10 months ago)
VPN Logon Failed: AAA user authentication Rejected user = <burzan>
Brute-Force
Exploited Host