๐ช๐ธ
librebit
2026-09-21 21:42:40
(4 days ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-09-06 10:53:26
(2 weeks ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-09-05 07:36:51
(2 weeks ago)
Brute force
Brute-Force
๐ซ๐ท
mrcrassi
2026-05-21 05:30:10
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
Tilellit.PRO
2026-05-17 06:50:01
(4 months ago)
Fail2Ban banned 45.148.124.74 for security violations in jail wp-armour. Log: 2026/05/17 06:50:00 [e ...
show more
Fail2Ban banned 45.148.124.74 for security violations in jail wp-armour. Log: 2026/05/17 06:50:00 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.148.124.74 | Target: wplogin" , client: 45.148.124.74, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฑ๐ป
garmtech.com
2026-05-12 06:50:46
(4 months ago)
IM360 WAF: SQL Injection via WordPress Link functionality MV:25"))/**/PROCEDURE/**/ANALYSE(EXTRACTVA ...
show more
IM360 WAF: SQL Injection via WordPress Link functionality MV:25"))/**/PROCEDURE/**/ANALYSE(EXTRACTVALUE(1135,/*!50000CONCAT*/(0x5c,%27~%27,(/*!50000SELECT*/(ELT(1135=1135,1))),%27~%27)),1) AND (("sPlTMxMc"="sPlTMxMc"
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-04-29 16:32:00
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 12:31:54.649695 2026] [security2:error] [pid 31751:tid 31751] [client 45.148.124.74:61715] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tannytalk.thoughtage.org|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tannytalk.thoughtage.org"] [uri "/s3cmd.ini"] [unique_id "afIyekAI0hsNo7B3gwJmpAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-04-29 03:12:22
(4 months ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 45.148.124.74 - - [29/Apr/2026:0 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 45.148.124.74 - - [29/Apr/2026:04:12:21 +0100] GET /s3cmd.ini HTTP/1.1 403 2777 - Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/532.8 (KHTML, like Gecko) Chrome/4.0.277.0 Safari/532.8
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 05:55:10
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 01:55:03.562750 2026] [security2:error] [pid 6660:tid 6703] [client 45.148.124.74:27753] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gorealtors.appraisalteam.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gorealtors.appraisalteam.net"] [uri "/s3cmd.ini"] [unique_id "afBLt35z3d5jt2OtTzhNEQAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 03:24:27
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 23:24:21.157937 2026] [security2:error] [pid 15961:tid 15961] [client 45.148.124.74:29733] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coroneta.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coroneta.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afAoZaMQwDAcepY0JNXnfgAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-04-27 21:36:37
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 17:56:00
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 13:55:55.645782 2026] [security2:error] [pid 24994:tid 24994] [client 45.148.124.74:25629] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dorioconnell.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dorioconnell.com"] [uri "/s3cmd.ini"] [unique_id "ae-jKxmpTKyxps_WJCDYdwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 00:50:31
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 20:50:24.222611 2026] [security2:error] [pid 24387:tid 24387] [client 45.148.124.74:19631] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puoci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puoci.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae6y0KfL7IwXKQiU25cWWwAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-25 17:41:10
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 13:41:06.859171 2026] [security2:error] [pid 3076:tid 3076] [client 45.148.124.74:63879] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fitnessdoctors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fitnessdoctors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aez8sgjP1Gg6GsBmJH8ZywAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 00:22:59
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.124.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 20:22:55.168118 2026] [security2:error] [pid 1129491:tid 1129491] [client 45.148.124.74:19521] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wickedworks.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wickedworks.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aeVx35fAsZMpB7ZepG4e3AAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack