Anonymous
2025-12-21 20:29:19
(5 months ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force
๐ต๐ฑ
tr1n
2025-12-07 04:12:41
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 206092 (SECFIREWALLAS)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 206092 (SECFIREWALLAS)
Protocol: HTTP/1.1 (GET method)
Endpoint: //wp-includes/wlwmanifest.xml
Timestamp: 2025-12-07T04:12:41Z
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
show less
Bad Web Bot
๐ง๐ช
cmbplf
2025-12-06 22:29:16
(5 months ago)
2.056 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
lindi
2025-12-06 18:28:47
(5 months ago)
Probing for resource vulnerabilities
...
Web Spam
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2025-12-03 00:25:07
(6 months ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2025-11-29 11:05:09
(6 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฟ
Tripwire
2025-11-11 13:55:48
(6 months ago)
Scanning for exploits - /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 08:10:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 03:10:07.827805 2025] [security2:error] [pid 6910:tid 6910] [client 45.130.83.69:30045] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crearcuestionarios.com"] [uri "/.env"] [unique_id "aRLvXwULA-ropC6D5vjcXQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 23:32:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 18:32:40.587948 2025] [security2:error] [pid 3003:tid 3055] [client 45.130.83.69:62313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalpartssolution.com"] [uri "/.env"] [unique_id "aRJ2GLT2gnbv2gQgc4rJNQAAAhc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 16:08:14
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 11:08:08.883329 2025] [security2:error] [pid 22804:tid 22804] [client 45.130.83.69:21545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fetchamreadingroom.org"] [uri "/.env"] [unique_id "aRIN6EnwQcK2WXt9KlOplgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2025-11-10 01:14:07
(6 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-09 02:47:18
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.130.83.69 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 21:47:13.654638 2025] [security2:error] [pid 31089:tid 31089] [client 45.130.83.69:23411] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rochesterhistorical.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rochesterhistorical.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aRAAsft0d0j9zB7rrNZJ6wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-11-04 23:46:00
(6 months ago)
1.377 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2025-11-04 22:51:53
(6 months ago)
Kingcopy(AI-IDS):IP is Probing for Wordpress vulnerabilities WTF:Banned
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-11-04 22:44:57
(6 months ago)
Multiple WAF Violations
Web App Attack