Anonymous
2026-05-04 16:56:29
(1 month ago)
Forum/form spam
Web Spam
๐ฑ๐ป
garmtech.com
2026-04-27 07:51:30
(1 month ago)
Multiple SASL authentication failures.
Brute-Force
๐ต๐ฑ
sefinek.net
2026-01-24 17:02:29
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฆ
Mediashaker
2025-12-22 19:39:47
(5 months ago)
(smtpauth) Failed SMTP AUTH login from 191.96.255.184 (US/United States/-)
Brute-Force
๐ฎ๐น
VHosting
2025-12-22 19:38:28
(5 months ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐บ๐ธ
octageeks.com
2025-11-03 05:08:02
(7 months ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-02 12:27:03
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 07:26:57.173351 2025] [security2:error] [pid 21186:tid 21186] [client 191.96.255.184:54327] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pappakotis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pappakotis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQdOEddo-gRo6pDAdvaAFgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-02 09:37:48
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 04:37:45.616923 2025] [security2:error] [pid 3009:tid 3009] [client 191.96.255.184:49096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||antcanada.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "antcanada.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQcmaUfGnLrIZiRdgMu0ywAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-02 03:25:50
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 23:25:45.435709 2025] [security2:error] [pid 28054:tid 28054] [client 191.96.255.184:3748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hardemancountyjournal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hardemancountyjournal.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQbPOXmfCJoqV4KTFhxUGwAAABM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-02 01:26:04
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 21:25:58.487300 2025] [security2:error] [pid 10238:tid 10238] [client 191.96.255.184:63051] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||otrantocapital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "otrantocapital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQazJl10oYpn6EfHfan9RwAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 21:09:29
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 17:09:24.436906 2025] [security2:error] [pid 2237:tid 2237] [client 191.96.255.184:27062] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kwijlen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kwijlen.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQZ3BEverNDtN33ESzrsmwAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-01 17:30:05
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-01 16:36:14
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 191.96.255.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 12:36:10.841668 2025] [security2:error] [pid 20236:tid 20236] [client 191.96.255.184:43017] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||phlippo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "phlippo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQY2-qhKFkTTzGXxBA2VHQAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-08-13 04:53:20
(10 months ago)
Blocked by UFW (TCP on 55756)
Source port: 54396
TTL: 56
Packet length: 64
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 55756)
Source port: 54396
TTL: 56
Packet length: 64
TOS: 0x08
This report (for 191.96.255.184) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ฟ๐ฆ
maximonline.co.za
2025-05-04 19:58:08
(1 year ago)
Brute Force SMTP AUTH Attack
Brute-Force