🇨🇭
4server
2026-09-10 00:46:39
(5 hours ago)
[ThuSep1002:46:33.3386952026][security2:error][pid224612:tid225116][client213.108.0.86:0]ModSecurity ...
show more
[ThuSep1002:46:33.3386952026][security2:error][pid224612:tid225116][client213.108.0.86:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"614\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"leonitraslochi.ch\"][uri\"/xmlrpc.php\"][unique_id\"aqH96ccoMxCRz4PFB4YtwQAAAQ0\"]
show less
Hacking
Web App Attack
🇨🇭
backslash
2026-08-28 14:57:01
(1 week ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇦🇺
paulshipley.com.au
2026-06-15 00:54:55
(2 months ago)
[Mon Jun 15 10:54:54.884339 2026] [security2:error] [pid 53985] [client 213.108.0.86:31433] [client ...
show more
[Mon Jun 15 10:54:54.884339 2026] [security2:error] [pid 53985] [client 213.108.0.86:31433] [client 213.108.0.86] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/xmlrpc.php"] [unique_id "ai9NXgbry4jrt0NlTeevhAAAAAY"]
...
show less
Web App Attack
🇺🇸
kosada.com
2026-05-01 11:48:26
(4 months ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2026-04-30 02:03:29
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 22:03:24.795285 2026] [security2:error] [pid 28892:tid 28892] [client 213.108.0.86:46227] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wendeeholtcamp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wendeeholtcamp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afK4bAawPLRO3nDOuiz--QAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
integrantservices.com
2026-04-26 12:00:39
(4 months ago)
(PERMBLOCK) 213.108.0.86 (RU/Russia/-) has had more than 4 temp blocks
Hacking
🇺🇸
integrantservices.com
2026-04-26 10:58:34
(4 months ago)
(wordpress) Failed wordpress login from 213.108.0.86 (RU/Russia/-)
Brute-Force
🇨🇿
ptlab
2026-04-21 00:49:52
(4 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
🇺🇸
nyt
2026-04-17 21:24:30
(4 months ago)
XMLRPC Attack, WP User Enumeration, WP Author Enumeration
Brute-Force
Web App Attack
🇺🇸
nationaleventpros.com
2026-04-17 11:04:00
(4 months ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-04-06 09:57:31
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 05:57:25.753850 2026] [security2:error] [pid 82693:tid 82693] [client 213.108.0.86:60303] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puoci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puoci.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adODhRwY23qRfCIarEUIBAAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-03 10:14:09
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 06:14:03.402798 2026] [security2:error] [pid 29893:tid 29893] [client 213.108.0.86:46469] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||curryfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "curryfirm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac-S60KzqDCG7dD_likHWAAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-28 02:37:22
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 22:37:15.599617 2026] [security2:error] [pid 27104:tid 27104] [client 213.108.0.86:14981] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||starfi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "starfi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acc-24os2t17-_FUJvHAoQAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
1gz
2025-12-29 11:44:33
(8 months ago)
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoin ...
show more
Triggered Cloudflare WAF (l7ddos) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
DDoS Attack
Bad Web Bot
🇩🇪
Packets-Decreaser.NET
2025-12-27 12:18:37
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam