๐บ๐ธ
TPI-Abuse
2026-02-18 18:36:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 13:36:52.869369 2026] [security2:error] [pid 1288110:tid 1288135] [client 45.3.35.238:54759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theyogicat.com"] [uri "/.env.staging"] [unique_id "aZYGxO9F_c7x5Ag_cn8wMAAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-18 14:06:01
(6 months ago)
Too many Status 40X (11)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 13:33:47
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 08:33:42.937007 2026] [security2:error] [pid 7950:tid 7950] [client 45.3.35.238:31269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisdomwfo.com"] [uri "/new/.git/config"] [unique_id "aZW_tvvEqYm_ZEWlBu08aQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 11:46:13
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 06:46:04.809977 2026] [security2:error] [pid 32227:tid 32227] [client 45.3.35.238:13775] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waltersnet.com"] [uri "/.env.save"] [unique_id "aZWmfG_ofAtvROBlg5fV2wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-02-14 08:15:05
(7 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-02-01 03:35:53
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.3.35.238 (US/United States/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.3.35.238 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-26 11:22:44
(7 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฎ๐น
VHosting
2025-12-23 20:20:15
(8 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐ง๐ช
cmbplf
2025-12-14 05:22:32
(9 months ago)
3.132 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2025-12-09 12:34:16
(9 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 04:56:29
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 23:56:25.344257 2025] [security2:error] [pid 5111:tid 5127] [client 45.3.35.238:26845] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreammile.info"] [uri "/.env"] [unique_id "aTO3eeMLhdNnCsv2kZVxngAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 10:43:28
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 05:43:21.726341 2025] [security2:error] [pid 29359:tid 29359] [client 45.3.35.238:56925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "postaltales.com"] [uri "/.env"] [unique_id "aTK3SR2NY72WDtSVby9tfwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 04:35:23
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.35.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 23:35:18.095207 2025] [security2:error] [pid 25483:tid 25483] [client 45.3.35.238:41145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sellitwithsteve.com"] [uri "/.svn/wc.db"] [unique_id "aTJhBm1k4_Bn9FtiW4k8AQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-13 22:28:48
(10 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐บ๐ธ
octageeks.com
2025-11-13 05:08:26
(10 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack