๐บ๐ธ
TPI-Abuse
2026-08-24 16:57:21
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:57:13.667746 2026] [security2:error] [pid 14293:tid 14293] [client 31.134.14.86:57983] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Chandler/Thumbs.db"] [unique_id "aox36e8N5YH4RcIXw8Rh4QAAABo"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Chandler/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 11:38:04
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 07:37:56.459011 2026] [security2:error] [pid 1951939:tid 1951939] [client 31.134.14.86:55881] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||austingrammer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "austingrammer.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ams3lKcMVfk4iLwarIipHwAAABs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 09:40:53
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 05:40:46.970312 2026] [security2:error] [pid 986020:tid 986020] [client 31.134.14.86:51417] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mordesign1.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mordesign1.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amscHg8ziMtR1Q9REazfyQAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-06-06 13:50:23
(2 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -56.442 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -56.442 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.4098.1
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 07:38:08
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.14.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 03:38:01.803261 2026] [security2:error] [pid 25681:tid 25681] [client 31.134.14.86:57343] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Steelcase/pics/LEAP/Thumbs.db"] [unique_id "ah_Z2T8cldGj3fk7hXSaOAAAACI"], referer: https://vitalitywebb.com/backstore/Steelcase/pics/LEAP/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-05-20 21:48:01
(3 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
๐จ๐ญ
backslash
2026-04-18 17:03:12
(4 months ago)
block ruleset 798ECF92F12ADC636D3520C2890AF17ADEFDE3BE
Bad Web Bot
๐ฉ๐ช
HandyTreff.de
2026-04-17 13:21:24
(4 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -57.377 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -57.377 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.1128.1
show less
Web App Attack
Bad Web Bot
๐ฎ๐น
VHosting
2026-03-17 12:50:03
(5 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
mrcrassi
2026-03-17 02:47:46
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: curl/8.6.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
masterguru
2025-12-23 11:01:01
(8 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 31.134.14.86 (FI/Finland/-): 1 in the last 360 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 31.134.14.86 (FI/Finland/-): 1 in the last 3600 secs (0-193)
show less
Hacking
๐จ๐ฆ
wil.com
2025-11-15 13:35:19
(9 months ago)
GlobalProtect login attempts with user leo.
VPN IP
Brute-Force
๐บ๐ธ
fbarela
2025-10-10 07:00:38
(10 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
Anonymous
2025-07-09 11:58:00
(1 year ago)
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2025-07-09 time=06:23:02 devname=FortiGate-200F devid=FG200FT922906136 eventtime=1752060183006324644 tz="-0500" logid="0101039426" type="event" subtype="vpn" level="alert" vd="root" logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=31.134.14.86 srccountry="United States" user="jimmy" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
VPN IP
Anonymous
2025-06-25 19:49:00
(1 year ago)
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fai ...
show more
Message meets Alert condition
The following critical firewall event was detected: SSL VPN login fail.
date=2025-06-25 time=14:24:35 devname=FortiGate-200F devid=FG200FT922906136 eventtime=1750879475604111355 tz="-0500" logid="0101039426" type="event" subtype="vpn" level="alert" vd="root" logdesc="SSL VPN login fail" action="ssl-login-fail" tunneltype="ssl-web" tunnelid=0 remip=31.134.14.86 srccountry="United States" user="sjohnson" group="N/A" dst_host="N/A" reason="sslvpn_login_unknown_user" msg="SSL user failed to logged in"
show less
VPN IP