๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(2 months ago)
"DDoS against public endpoint"
DDoS Attack
๐บ๐ธ
interbiznw.com
2026-03-16 18:02:55
(2 months ago)
wordpress-fuzzing
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ต๐ฑ
sefinek.net
2025-12-22 22:42:09
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-12-08 09:43:12
(6 months ago)
botnet
DDoS Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 03:38:15
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 22:38:09.389308 2025] [security2:error] [pid 20473:tid 20473] [client 45.3.37.221:19487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tonysargbooks.banis-associates.com"] [uri "/.git/HEAD"] [unique_id "aSUkocugMIgrNUNl9Bd2UAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 02:27:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 21:27:03.555899 2025] [security2:error] [pid 27727:tid 27742] [client 45.3.37.221:41641] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.stateabbreviationlist.com"] [uri "/.git/HEAD"] [unique_id "aSUT9_eXMnwYTnmV60PTGQAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:53:22
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:53:16.216602 2025] [security2:error] [pid 12506:tid 12506] [client 45.3.37.221:54857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fantasysportstherapy.michaelward.com"] [uri "/.svn/wc.db"] [unique_id "aSUMDBYLuZ3OqplRtITXdQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 01:32:55
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.37.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 20:32:47.777474 2025] [security2:error] [pid 1647141:tid 1647224] [client 45.3.37.221:40121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tapdd.com"] [uri "/.env"] [unique_id "aSUHP9ffCdpZ5cNrCNdToQAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
techboy117
2025-11-14 00:06:07
(6 months ago)
Blocking due to password spraying.
Brute-Force
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-11-07 10:39:06
(7 months ago)
WP Login Scan Activities
Web App Attack
Anonymous
2025-10-28 23:10:22
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-10-28 20:06:04
(7 months ago)
wordpress-trap
Web App Attack
๐จ๐ญ
backslash
2025-10-16 08:45:13
(7 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐จ๐ฆ
wil.com
2025-10-14 12:44:18
(7 months ago)
GlobalProtect login attempts with user callesa.
VPN IP
Brute-Force
Anonymous
2025-10-14 00:50:08
(7 months ago)
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failu ...
show more
Dictionary attack on Palo Alto GlobalProtect VPN portal (port 443) detected via repeated login failures with varying usernames.
show less
Brute-Force