๐ต๐ฑ
sefinek.net
2026-04-02 04:21:00
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:114.0) Gecko/20100101 Firefox/114.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-05 08:07:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.50.249 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.50.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 03:07:36.086334 2026] [security2:error] [pid 2915:tid 2937] [client 45.3.50.249:61243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howardhallis.com"] [uri "/.git/objects/8a/8f5ded2214a2cd3dbd2275fe8f3e416d264e5e"] [unique_id "aak5yGbdh7c6FWT9QFVL6gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
[email protected]
2026-03-04 00:28:36
(3 months ago)
45.3.50.249 - - [04/Mar/2026:00:15:45 +0000] "GET /.env HTTP/1.1" 404 332 "http://academy.scotland-e ...
show more
45.3.50.249 - - [04/Mar/2026:00:15:45 +0000] "GET /.env HTTP/1.1" 404 332 "http://academy.scotland-excel.org.uk/.env" "Go-http-client/1.1"
45.3.50.249 - - [04/Mar/2026:00:25:34 +0000] "GET /.git/objects/65/1e576d38d5d9b910221fe2c44bd8c16fa156ae HTTP/1.1" 404 332 "http://academy.scotland-excel.org.uk/.git/objects/65/1e576d38d5d9b910221fe2c44bd8c16fa156ae" "Go-http-client/1.1"
45.3.50.249 - - [04/Mar/2026:00:28:36 +0000] "GET /.git/objects/c5/d0ed4bea65f0f9d3fd3c8d68496d4ebad24788 HTTP/1.1" 404 332 "http://academy.scotland-excel.org.uk/.git/objects/c5/d0ed4bea65f0f9d3fd3c8d68496d4ebad24788" "Go-http-client/1.1"
...
show less
Web App Attack
๐บ๐ธ
fbarela
2026-01-25 04:01:00
(4 months ago)
FortiGate SSL VPN login failures.
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-01-09 13:47:43
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.3.50.249 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.3.50.249 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 09 08:47:35.964088 2026] [security2:error] [pid 23177:tid 23177] [client 45.3.50.249:54965] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.neff.family.name|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.neff.family.name"] [uri "/db.sql"] [unique_id "aWEG90U_Fq5mucuAeIY4LwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-14 12:36:24
(6 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
Anonymous
2025-11-07 08:02:34
(7 months ago)
[redacted] 45.3.50.249 - - [07/Nov/2025:09:02:20 +0100] "POST /xmlrpc.php HTTP/2.0" 200 445 "-" "Moz ...
show more
[redacted] 45.3.50.249 - - [07/Nov/2025:09:02:20 +0100] "POST /xmlrpc.php HTTP/2.0" 200 445 "-" "Mozilla/5.0 (Linux; Android 7.0; Moto C) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.80 Mobile Safari/537.36"
[redacted] 45.3.50.249 - - [07/Nov/2025:09:02:22 +0100] "POST /xmlrpc.php HTTP/2.0" 200 445 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.8) Gecko/20061025 Firefox/1.5.0.8"
[redacted] 45.3.50.249 - - [07/Nov/2025:09:02:23 +0100] "POST /xmlrpc.php HTTP/2.0" 200 445 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_2_6 like Mac OS X) AppleWebKit/604.5.6 (KHTML, like Gecko) Version/11.0 Mobile/15D100 Safari/604.1"
[redacted] 45.3.50.249 - - [07/Nov/2025:09:02:24 +0100] "POST /xmlrpc.php HTTP/2.0" 200 445 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.0.3705)"
[redacted] 45.3.50.249 - - [07/Nov/2025:09:02:26 +0100] "POST /xmlrpc.php HTTP/2.0" 200 445 "-" "Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident
...
show less
Hacking
Web App Attack
๐ง๐ช
madeit
2025-11-04 16:45:58
(7 months ago)
Web App Attack
๐ซ๐ท
applemooz
2025-11-01 11:53:43
(7 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2025-10-29 20:08:14
(7 months ago)
Brute-Force
Anonymous
2025-10-16 06:28:15
(7 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-10-15 10:51:47
(7 months ago)
GlobalProtect login attempts with user eedodson.
VPN IP
Brute-Force
Anonymous
2025-10-07 09:38:40
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.07 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.07 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-05 07:03:27
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.05 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.10.05 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-10-03 23:30:26
(8 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.03 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2025.10.03 is noted in report timestamp
show less
Hacking
Brute-Force