๐ซ๐ท
masterguru
2026-06-20 09:37:53
(16 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.130.203.178 (EG/Egypt/-): 1 in the ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.130.203.178 (EG/Egypt/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
COMAITE
2026-06-20 02:17:03
(23 hours ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 01:58:00
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 21:57:53.139627 2026] [security2:error] [pid 2767:tid 2767] [client 45.130.203.178:22929] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dorismitchell.com.billymitchell.com"] [uri "/.git/HEAD"] [unique_id "ajXzoU82FgdA4E-PGNWFBAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-06-19 13:07:00
(1 day ago)
Probing for .env file:
45.130.203.178 - - [19/Jun/2026:15:06:59 +0200] "GET /.env.production HTTP/1. ...
show more
Probing for .env file:
45.130.203.178 - - [19/Jun/2026:15:06:59 +0200] "GET /.env.production HTTP/1.1" 403 146 "-" "Python-urllib/3.10"
show less
Web App Attack
๐ฌ๐ง
Axel
2026-06-19 10:29:50
(1 day ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ซ๐ฎ
as211431.net
2026-06-19 00:08:57
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.env
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-18 00:20:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 20:20:49.467524 2026] [security2:error] [pid 2050:tid 2050] [client 45.130.203.178:62019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miscfiles.praemiumtech.com"] [uri "/.git/HEAD"] [unique_id "ajM54erR3yeqOZwTPbQ3fgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 19:56:21
(1 week ago)
45.130.203.178 - - [10/Jun/2026:21:56:15 +0200] "GET /wp-includes/sitemaps/wp-conflg.php HTTP/1.1" 4 ...
show more
45.130.203.178 - - [10/Jun/2026:21:56:15 +0200] "GET /wp-includes/sitemaps/wp-conflg.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626.121 Safari/537.36"
45.130.203.178 - - [10/Jun/2026:21:56:15 +0200] "GET /wp-includes/assets/wp-includes/assets/script-loader-packages.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
45.130.203.178 - - [10/Jun/2026:21:56:15 +0200] "GET /wp-includes/SimplePie/login.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
45.130.203.178 - - [10/Jun/2026:21:56:15 +0200] "GET /network.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Linux x86_64; rv:79.0) Gecko/20100101 Firefox/79.0"
45.130.203.178 - - [10/Jun/2026:21:56:15 +0200] "GET /wp-admin/css/colors/blue/alfa.php HTTP/1.1" 404 482 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, l
...
show less
DDoS Attack
๐ท๐บ
sms.ru
2026-06-10 17:52:21
(1 week ago)
/wp-admin/images/index.php
Web App Attack
๐ซ๐ท
Octopuce
2026-06-10 15:53:29
(1 week ago)
Aggressive web search of vulnerable pages: /wp-admin/css/autoload_classmap.php /wp_wlx.php /wp-admin ...
show more
Aggressive web search of vulnerable pages: /wp-admin/css/autoload_classmap.php /wp_wlx.php /wp-admin/js/wp-conflg.php /wp-includes/assets/husky ...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 21:59:07
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-07.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-06-07 03:06:25
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
aks4226
2026-05-24 04:46:27
(3 weeks ago)
Attacking common web applications. (n01)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 10:33:20
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.178 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.178 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 06:33:14.165952 2026] [security2:error] [pid 16008:tid 16008] [client 45.130.203.178:52713] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medusakenya.illumoonatedtarot.com"] [uri "/.git/HEAD"] [unique_id "ahGCamxG0kEa92cDZWkdmgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-05-23 05:59:44
(4 weeks ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/HEAD Se ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/HEAD Server: UK-01
show less
Web App Attack
Hacking
SQL Injection