๐ช๐ธ
librebit
2026-05-17 05:15:35
(2 weeks ago)
Brute force
Brute-Force
๐ซ๐ท
Security_Whaller
2026-04-27 13:56:43
(1 month ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack
Anonymous
2026-03-03 02:08:53
(3 months ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-30 01:12:08
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 29 20:12:02.780123 2026] [security2:error] [pid 1402:tid 1402] [client 45.3.50.187:32809] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||primacomm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "primacomm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXwFYk0OeUTeLGJKC3oFBgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2025-12-14 12:04:39
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Fedora; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-11 04:02:07
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 23:02:01.090648 2025] [security2:error] [pid 12913:tid 12913] [client 45.3.50.187:31759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mnspiritwear.com"] [uri "/.env"] [unique_id "aTpCOVEAowL-LNSqvUewFgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 06:15:31
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 01:15:27.352636 2025] [security2:error] [pid 13229:tid 13229] [client 45.3.50.187:18599] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "depthsofsatan.com"] [uri "/.svn/wc.db"] [unique_id "aTe-f9V8YsK8g1iZYnBhyAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-07 14:13:44
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 09:13:38.476007 2025] [security2:error] [pid 31664:tid 31670] [client 45.3.50.187:13931] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "munatseng.org"] [uri "/.env"] [unique_id "aTWLkq027dfle2I--N1k4gAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-12-07 04:54:19
(5 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /.env]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 15:55:44
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 10:55:40.366815 2025] [security2:error] [pid 25101:tid 25101] [client 45.3.50.187:13571] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "activethinkers.net"] [uri "/.env"] [unique_id "aTRR_EOlYfIMJwYD7AG5TgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-06 11:53:03
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 06:52:59.582244 2025] [security2:error] [pid 27460:tid 27484] [client 45.3.50.187:27175] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catslife.net"] [uri "/.git/HEAD"] [unique_id "aTQZGyYePA-QtpA1uK4xCAAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Shaik Sai Meera
2025-12-06 11:40:09
(6 months ago)
IM360 WAF: Hidden file access
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-05 14:23:59
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 09:23:52.999526 2025] [security2:error] [pid 2937:tid 2937] [client 45.3.50.187:29469] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "happyskinhappylife.com"] [uri "/.env"] [unique_id "aTLq-CmtSj18qU4QboJJNgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 08:38:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.187 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 03:38:44.972640 2025] [security2:error] [pid 27387:tid 27387] [client 45.3.50.187:23435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "napkinsforweddings.com"] [uri "/.svn/wc.db"] [unique_id "aTKaFKjyURWAq-yNG18fbQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-04 03:23:01
(6 months ago)
2025-12-04T05:23:00.664767+02:00 zanati wp(www.sahpa.co.za)[382755]: Blocked authentication attempt ...
show more
2025-12-04T05:23:00.664767+02:00 zanati wp(www.sahpa.co.za)[382755]: Blocked authentication attempt for [email protected] from 45.3.50.187
...
show less
Web App Attack