π«π·
Sklurk
2026-07-17 10:19:11
(1 week ago)
Web App Attack
Web App Attack
π«π·
mrcrassi
2026-07-05 20:02:24
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¦πΊ
RedBear IT
2026-03-26 10:00:37
(4 months ago)
"DDoS against public endpoint"
DDoS Attack
πΊπΈ
TPI-Abuse
2025-12-26 10:51:18
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 26 05:51:12.325791 2025] [security2:error] [pid 17551:tid 17551] [client 45.3.34.49:36527] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aU5ooOeHa7la2acC1T8wmAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-12 14:22:25
(7 months ago)
botnet
DDoS Attack
πΊπΈ
TPI-Abuse
2025-11-25 02:39:38
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:39:34.168897 2025] [security2:error] [pid 23581:tid 23581] [client 45.3.34.49:10147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dalebeyer.com"] [uri "/.env"] [unique_id "aSUW5oUif345xuXsfQqihAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 08:39:23
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:39:10.269336 2025] [security2:error] [pid 17893:tid 17893] [client 45.3.34.49:38055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.johnatuttle.com"] [uri "/.svn/wc.db"] [unique_id "aSQZrmY6c6aa0EJkIEdXHwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:18:54
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:18:46.140813 2025] [security2:error] [pid 3650:tid 3650] [client 45.3.34.49:31989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aroilcontrolsystem.com"] [uri "/.env"] [unique_id "aSQG1l2aV-lFVOfpYPzJbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:01:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:01:14.605199 2025] [security2:error] [pid 22941:tid 22941] [client 45.3.34.49:28795] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terrybeachmusic.danged.com"] [uri "/.svn/wc.db"] [unique_id "aSP0qkyr3TL-T8z8Dtei3gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:49:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:49:16.042696 2025] [security2:error] [pid 6651:tid 6651] [client 45.3.34.49:15517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.caringforwomenlq.com"] [uri "/.svn/wc.db"] [unique_id "aSPjzPWAN1P9_rFEsYSiegAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:27:15
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.34.49 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:27:11.138141 2025] [security2:error] [pid 24467:tid 24467] [client 45.3.34.49:31867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.critrs.com"] [uri "/.svn/wc.db"] [unique_id "aSPen_G6OACjvfiVfPijcAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-16 07:08:18
(8 months ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.11.16 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.11.16 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-11-14 06:32:42
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
π«π·
applemooz
2025-11-01 11:13:03
(8 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
π©πͺ
Marc
2025-10-29 20:10:54
(8 months ago)
Brute-Force