๐ฑ๐ป
garmtech.com
2026-04-25 14:50:59
(1 month ago)
IM360 WAF: WordPress malicious plugin install block MV:dummy-plugin.zip
Web App Attack
๐ซ๐ท
masterguru
2026-04-23 11:53:10
(1 month ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.3.46.225 (CA/Canada/-): 1 in the last 3600 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.3.46.225 (CA/Canada/-): 1 in the last 3600 secs (0-193)
show less
Hacking
๐ซ๐ท
masterguru
2026-04-18 14:45:54
(1 month ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.3.46.225 (CA/Canada/-): 1 in the last 3600 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.3.46.225 (CA/Canada/-): 1 in the last 3600 secs (0-193)
show less
Hacking
๐ต๐ฑ
sefinek.net
2025-12-22 21:49:10
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12.5; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-10 14:52:11
(5 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
Anonymous
2025-12-02 13:17:18
(6 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 07:05:46
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 02:05:40.712401 2025] [security2:error] [pid 12468:tid 12468] [client 45.3.46.225:35009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dwightbrown.com"] [uri "/.git/HEAD"] [unique_id "aS6PxHzI0UjEIthbpYTXHAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 05:50:45
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 00:50:38.165391 2025] [security2:error] [pid 14956:tid 15010] [client 45.3.46.225:23707] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikall.com"] [uri "/.env"] [unique_id "aS5-Llbve-zJwfI7DO8MDgAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 09:30:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 04:29:58.120987 2025] [security2:error] [pid 25511:tid 25511] [client 45.3.46.225:11163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sifnosgreekcatering.com"] [uri "/.git/HEAD"] [unique_id "aSQlltslJ1vRDrfaEAba8QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 07:22:38
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:22:34.991031 2025] [security2:error] [pid 15119:tid 15119] [client 45.3.46.225:18917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.microkerneltechnologies.com"] [uri "/.svn/wc.db"] [unique_id "aSQHuk3hOQo2aePHtVr9FQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-24 04:31:05
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.46.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:31:00.497182 2025] [security2:error] [pid 1736:tid 1736] [client 45.3.46.225:9029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.octitlerep.com"] [uri "/.env"] [unique_id "aSPfhD5rbKq0w4stQo6BfgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-21 18:53:32
(6 months ago)
This IP was involved in an brute force and password spray attack on 2025/11/21 12:35:08
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-10-29 00:51:03
(7 months ago)
WP Login Scan Activities
Web App Attack
๐ณ๐ฑ
GabrielJST
2025-10-10 21:36:56
(7 months ago)
(sshd) Failed SSH login from 45.3.46.225 (CA/Canada/-)
Brute-Force
SSH
๐ฉ๐ช
Admins@FBN
2025-10-06 20:04:35
(7 months ago)
FW-PortScan: Traffic Blocked srcport=9797 dstport=22
Port Scan
Hacking
SSH