Anonymous
2026-07-16 23:49:52
(2 months ago)
[da.kdns.gr] httpd-login-spray-site: sites=www.xamogelo.edu.gr; logs=/var/log/httpd/domains/xamogelo ...
show more
[da.kdns.gr] httpd-login-spray-site: sites=www.xamogelo.edu.gr; logs=/var/log/httpd/domains/xamogelo.edu.gr.log; samples=site_wide=true | distinct_ips=24 | /wp-login.php
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-07-15 04:55:55
(2 months ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 05:13:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 01:13:09.407424 2026] [security2:error] [pid 12838:tid 12838] [client 45.130.203.195:58443] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jerome.mousseron.com"] [uri "/.git/HEAD"] [unique_id "alXFZT_QYu1w-k3SSS6iKQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-13 23:53:05
(2 months ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
NL/Netherlands/-
Web App Attack
๐บ๐ธ
MPL
2026-06-30 03:15:39
(2 months ago)
tcp/443 (3 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-27 12:27:19
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 08:27:11.461631 2026] [security2:error] [pid 17946:tid 17946] [client 45.130.203.195:41763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greensealusa.stormstrips.com"] [uri "/.env.production"] [unique_id "aj_Bn7802V5qMMxLBxUVwgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 15:49:28
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 11:49:24.426777 2026] [security2:error] [pid 24813:tid 24813] [client 45.130.203.195:30239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hawaiivacations.com"] [uri "/.env"] [unique_id "aj6fhLDtoa0NeQN2d6PbuAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 09:20:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 05:20:36.794106 2026] [security2:error] [pid 20975:tid 20975] [client 45.130.203.195:31379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eclipsesoftware.biz"] [uri "/.env"] [unique_id "aj5EZPS0eev5_6lpFLaH3QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 07:03:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 03:03:25.863791 2026] [security2:error] [pid 13419:tid 13419] [client 45.130.203.195:22699] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cybersoftware.org"] [uri "/.env.production"] [unique_id "aj4kPZlUE2MYOOHu32woWQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 02:31:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 22:31:25.234312 2026] [security2:error] [pid 5976:tid 5991] [client 45.130.203.195:24777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tamarkummel.com.captainpurpleproductions.com"] [uri "/.git/HEAD"] [unique_id "aj3kfapy_OxlyvtvJffnxAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 23:10:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 19:10:15.241849 2026] [security2:error] [pid 19015:tid 19015] [client 45.130.203.195:52273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.discountbusinessholidaycards.com"] [uri "/.env"] [unique_id "aj21V-ad1FXa3H7GodjkQwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 16:52:48
(3 months ago)
45.130.203.195 - - [26/Jun/2026:00:52:47 +0800] "GET /.git/HEAD HTTP/1.1" 301 240 "-" "Python-urllib ...
show more
45.130.203.195 - - [26/Jun/2026:00:52:47 +0800] "GET /.git/HEAD HTTP/1.1" 301 240 "-" "Python-urllib/3.10"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 16:47:27
(3 months ago)
[25/Jun/2026:16:47:26 +0000] host=test.lovelyrender.com server=test.lovelyrender.com ip=45.130.203.1 ...
show more
[25/Jun/2026:16:47:26 +0000] host=test.lovelyrender.com server=test.lovelyrender.com ip=45.130.203.195 method=GET req=/.git/HEAD uri=/index.php status=404 bytes=62855 rt=0.056 urt=0.056 ref="-" ua="Python-urllib/3.10"
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
mrcrassi
2026-06-25 16:35:02
(3 months ago)
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint ...
show more
Triggered Cloudflare WAF (bic) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
UA: Python-urllib/3.10
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-25 02:07:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:07:20.202666 2026] [security2:error] [pid 4863:tid 4863] [client 45.130.203.195:53179] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thegoldreserve.com"] [uri "/.env"] [unique_id "ajyNWOczT2cKgNrxGuuDygAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack