๐บ๐ธ
TPI-Abuse
2026-07-13 20:37:31
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 16:37:26.157708 2026] [security2:error] [pid 29047:tid 29047] [client 194.104.8.109:65527] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tgcindustrial.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tgcindustrial.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alVMhsVqgpyxigaa5vhqwAAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-06-28 07:16:31
(2 months ago)
Fail2Ban banned 194.104.8.109 for security violations in jail wp-armour. Log: 2026/06/28 07:16:31 [e ...
show more
Fail2Ban banned 194.104.8.109 for security violations in jail wp-armour. Log: 2026/06/28 07:16:31 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 194.104.8.109 | Target: wplogin" , client: 194.104.8.109, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-19 19:45:10
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 15:45:05.879881 2026] [security2:error] [pid 7844:tid 7844] [client 194.104.8.109:53279] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kmp.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kmp.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajWcQZ3xi9Qv83Eg-CKrWAAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
Yashgarg@123
2026-06-18 06:42:00
(2 months ago)
this ip address "194.104.8.109" is trying to compromise the environment and tried DDOS and Brute For ...
show more
this ip address "194.104.8.109" is trying to compromise the environment and tried DDOS and Brute Force Attack
show less
DDoS Attack
Brute-Force
๐จ๐ญ
backslash
2026-06-15 12:36:00
(2 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TRoden
2026-04-08 10:01:09
(4 months ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
๐ซ๐ท
mrcrassi
2026-04-07 10:17:49
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: curl/7.88.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
kjaerulff
2026-03-11 14:10:59
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-23 05:28:42
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 23 00:28:37.307565 2026] [security2:error] [pid 21642:tid 21642] [client 194.104.8.109:44227] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||allfloridamedia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "allfloridamedia.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXMHBSsTXi6Rjots67nqfQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-23 02:52:46
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 21:52:41.509524 2026] [security2:error] [pid 26357:tid 26357] [client 194.104.8.109:23717] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bikinitweets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bikinitweets.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXLieY1xmcXYIGhLwBqxmQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 23:18:32
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 194.104.8.109 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 18:18:28.084995 2026] [security2:error] [pid 5526:tid 5526] [client 194.104.8.109:53449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodandreelpiercam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodandreelpiercam.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXKwRNMMPuFkRP1zGfGDTAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-17 16:50:52
(9 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐จ๐ฟ
lp
2025-11-07 17:51:23
(9 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.109
2025-11-07T18:23:10+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.109
2025-11-07T18:23:10+01:00 vpn Access-Reject 'cisco' station: 194.104.8.109 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-11-02 14:50:37
(10 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.109
2025-11-02T14:29:57+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.109
2025-11-02T14:29:57+01:00 vpn Access-Reject 'aksoxford' station: 194.104.8.109 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-10-30 10:25:58
(10 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.109
2025-10-30T10:51:02+01: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 194.104.8.109
2025-10-30T10:51:02+01:00 vpn Access-Reject 'Fazile' station: 194.104.8.109 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack