๐ฒ๐พ
Rizzy
2026-08-09 10:59:11
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-07 09:51:04
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-31 06:35:35
(1 month ago)
[Fri Jul 31 16:35:34.577277 2026] [security2:error] [pid 623280] [client 198.154.80.124:44742] [clie ...
show more
[Fri Jul 31 16:35:34.577277 2026] [security2:error] [pid 623280] [client 198.154.80.124:44742] [client 198.154.80.124] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/wp-content/plugins/woo-conditional-shipping-pro/frontend/css/woo-conditional-shipping.css"] [unique_id "amxCNtEy9cae-CxW6qM6mQAAAAk"], referer: https://ccideas.com.au/my-account/?action=register
...
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-29 20:03:51
(1 month ago)
[Thu Jul 30 06:03:49.978607 2026] [security2:error] [pid 440866] [client 198.154.80.124:59738] [clie ...
show more
[Thu Jul 30 06:03:49.978607 2026] [security2:error] [pid 440866] [client 198.154.80.124:59738] [client 198.154.80.124] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/xmlrpc.php"] [unique_id "ampcpWrB50KFBtwIWuP6NAAAAAs"], referer: https://paulshipley.com.au/xmlrpc.php?rsd
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-24 17:33:37
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-23 11:51:32
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-18 15:07:46
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐จ๐ญ
4server
2026-07-18 05:15:54
(1 month ago)
[SatJul1807:15:48.7095962026][security2:error][pid3473400:tid3473431][client198.154.80.124:0]ModSecu ...
show more
[SatJul1807:15:48.7095962026][security2:error][pid3473400:tid3473431][client198.154.80.124:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"www.vetreriaperletti.ch\"][uri\"/xmlrpc.php\"][unique_id\"alsMBBQzFpg8CxQZ1uqO0wAAAII\"]\,referer:https://www.vetreriaperletti.ch/
show less
Hacking
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-17 03:16:58
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ต๐ฑ
sefinek.net
2026-04-02 12:13:36
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /genshin-stella-mod | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1264.71 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฑ๐ป
garmtech.com
2026-03-10 07:40:34
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-40.198.154.80.124.web-spamm ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 09-40.198.154.80.124.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2025-11-09 17:52:51
(10 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ป๐ณ
Xuan Can
2023-10-27 22:05:21
(2 years ago)
(mod_security) mod_security (id:6) triggered by 198.154.80.124 (NL/Netherlands/s124.therabox.net): 1 ...
show more
(mod_security) mod_security (id:6) triggered by 198.154.80.124 (NL/Netherlands/s124.therabox.net): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 28 05:05:14.619926 2023] [security2:error] [pid 39062:tid 47776421398272] [client 198.154.80.124:48688] [client 198.154.80.124] ModSecurity: Access denied with connection close (phase 2). Pattern match "wp-login.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "63"] [id "6"] [severity "CRITICAL"] [hostname "kb.pavietnam.vn"] [uri "/wp-login.php"] [unique_id "ZTw0GranDD-Hs6PLj0i1BQAAAIY"], referer: https://kb.pavietnam.vn/wp-login.php?action=register
show less
Brute-Force
SSH
๐ป๐ณ
Xuan Can
2023-10-12 04:59:19
(2 years ago)
(mod_security) mod_security (id:6) triggered by 198.154.80.124 (NL/Netherlands/s124.therabox.net): 1 ...
show more
(mod_security) mod_security (id:6) triggered by 198.154.80.124 (NL/Netherlands/s124.therabox.net): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 12 11:59:12.026203 2023] [security2:error] [pid 18752:tid 46998677214976] [client 198.154.80.124:46355] [client 198.154.80.124] ModSecurity: Access denied with connection close (phase 2). Pattern match "wp-login.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "63"] [id "6"] [severity "CRITICAL"] [hostname "kb.pavietnam.vn"] [uri "/wp-login.php"] [unique_id "ZSd9IOQhg-Z0QaLmtUfoLgAAAEY"], referer: https://kb.pavietnam.vn/
show less
Brute-Force
SSH
๐ป๐ณ
Xuan Can
2023-10-10 07:00:52
(2 years ago)
(mod_security) mod_security (id:6) triggered by 198.154.80.124 (NL/Netherlands/s124.therabox.net): 1 ...
show more
(mod_security) mod_security (id:6) triggered by 198.154.80.124 (NL/Netherlands/s124.therabox.net): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 10 14:00:47.280977 2023] [security2:error] [pid 16662:tid 46940155004672] [client 198.154.80.124:37452] [client 198.154.80.124] ModSecurity: Access denied with connection close (phase 2). Pattern match "wp-login.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "63"] [id "6"] [severity "CRITICAL"] [hostname "kb.pavietnam.vn"] [uri "/wp-login.php"] [unique_id "ZST2n0zYxYY0zNMG-ERX-wAAAJQ"], referer: https://kb.pavietnam.vn/
show less
Brute-Force
SSH