๐ฆ๐บ
MAGIC
2026-06-24 05:04:37
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-06-22 16:50:05
(2 months ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-06-22 16:44:36
(2 months ago)
Fail2Ban triggered
Web App Attack
๐ฆ๐บ
oncord
2026-05-03 07:27:34
(4 months ago)
Form spam
Web Spam
๐ฆ๐บ
MAGIC
2026-04-05 03:18:31
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 17:45:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 13:45:42.921310 2026] [security2:error] [pid 23965:tid 24051] [client 45.130.81.3:46845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nobletitles.org"] [uri "/sftp-config.json"] [unique_id "abbwRhm-rIL89F8NN-qlFgAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-03-09 16:59:11
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฌ๐ง
pinguin
2026-03-03 14:07:07
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from UA.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from UA.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /backup/backup.sql
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-02-25 23:46:09
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 18:46:04.190140 2026] [security2:error] [pid 23601:tid 23601] [client 45.130.81.3:27187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||highstakeslearning.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "highstakeslearning.com"] [uri "/back/www.sql"] [unique_id "aZ-JvG6JCtnd3Cx5D7uUXQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 05:57:11
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 00:57:04.230695 2026] [security2:error] [pid 11501:tid 11501] [client 45.130.81.3:22365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intercotrading.com"] [uri "/old/sftp-config.json"] [unique_id "aZvsMP3L3V_ZT3LGTU1ufQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 02:15:24
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 21:15:20.031102 2026] [security2:error] [pid 19838:tid 19838] [client 45.130.81.3:63449] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casinoaffiliateprogramsonline.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casinoaffiliateprogramsonline.com"] [uri "/backups/backup.sql"] [unique_id "aZUguHyZIcb9Ed_zWGxttgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 14:45:02
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 09:44:55.309523 2026] [security2:error] [pid 10543:tid 10543] [client 45.130.81.3:25051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usbea.com"] [uri "/backup/sftp-config.json"] [unique_id "aZHb5w8s0_NN0PdQEkTB0wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 14:38:47
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.130.81.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 09:38:43.063166 2026] [security2:error] [pid 11330:tid 11330] [client 45.130.81.3:43209] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||loriatrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "loriatrading.com"] [uri "/back/backup.sql"] [unique_id "aY3l80Y5OqgH2SCSK4YXmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
island-freaks.com
2026-01-23 06:33:30
(7 months ago)
Attack Type: WordPress Exploit Bot attempt on /old/config.json | DNS 45.130.81.3 | Agent: none
Port Scan
Hacking
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
Penny Packer
2025-12-15 16:18:37
(8 months ago)
Fail2Ban apache-tripwires
Web App Attack