๐ซ๐ท
Sklurk
2026-08-09 03:21:39
(1 week ago)
Web App Attack
Web App Attack
๐บ๐ธ
cwytech
2026-07-30 16:11:16
(3 weeks ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-07-30 12:26:53
(3 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Apache probe; attempts=21; exact paths: /xmlrpc.php
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-07-25 03:39:58
(4 weeks ago)
[Sat Jul 25 05:39:53.491582 2026] [authz_core:error] [pid 1009085:tid 1009085] [client 45.3.40.112:4 ...
show more
[Sat Jul 25 05:39:53.491582 2026] [authz_core:error] [pid 1009085:tid 1009085] [client 45.3.40.112:46605] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: http://alex-eventfahrten.de/wp-login.php
[Sat Jul 25 05:39:54.420865 2026] [authz_core:error] [pid 1078659:tid 1078659] [client 45.3.40.112:49499] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2026-07-12 04:53:53
(1 month ago)
Web App Attack
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-24 10:28:06
(1 month ago)
Wordfence waf block on illinoisvoices
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-06-23 12:38:22
(1 month ago)
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 45.3.40.112 - - [23/Jun/2026:13:38:15 +0100] POS ...
show more
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 45.3.40.112 - - [23/Jun/2026:13:38:15 +0100] POST /wp-login.php HTTP/1.1 200 7132 https://[REDACTED_DOMAIN]/wp-login.php Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
๐ฉ๐ช
4server
2026-04-21 05:47:33
(4 months ago)
[TueApr2107:47:26.9093542026][security2:error][pid3025358:tid3025366][client45.3.40.112:0]ModSecurit ...
show more
[TueApr2107:47:26.9093542026][security2:error][pid3025358:tid3025366][client45.3.40.112:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"gualandi.ch\"][uri\"/db.sql\"][unique_id\"aecPbhhJ3UcICK2T19x-SgAAAQU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-31 00:59:12
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-11-25 07:25:54
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:25:48.911000 2025] [security2:error] [pid 7228:tid 7228] [client 45.3.40.112:39359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.scrunchiebutt.com"] [uri "/.git/HEAD"] [unique_id "aSVZ_GJVAMTj7ut-6G9ZVAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 07:01:49
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 02:01:42.891641 2025] [security2:error] [pid 5830:tid 5830] [client 45.3.40.112:49005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lapetitegrooming.com"] [uri "/.git/HEAD"] [unique_id "aSVUVk_eQujDbeYUWrc2OwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 06:15:28
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 01:15:20.009816 2025] [security2:error] [pid 27048:tid 27048] [client 45.3.40.112:10019] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.pericles21.com"] [uri "/.env"] [unique_id "aSVJePQwy0DqJDFyoSSzSwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 05:54:55
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 25 00:54:51.623326 2025] [security2:error] [pid 4002:tid 4002] [client 45.3.40.112:24293] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.yankeetownfishing.com"] [uri "/.git/HEAD"] [unique_id "aSVEq50sX-99X0OxrjP5wAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-25 04:46:23
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 23:46:04.481836 2025] [security2:error] [pid 804441:tid 804441] [client 45.3.40.112:51899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pasamugo.com"] [uri "/.git/HEAD"] [unique_id "aSU0jHtiofPVcQQsVpBNZQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack