๐บ๐ธ
TPI-Abuse
2026-06-11 05:58:41
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.41.104.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 45.41.104.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 01:58:26.292815 2026] [security2:error] [pid 7275:tid 7275] [client 45.41.104.232:62648] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.41.104.232 (+1 hits since last alert)|ohanameetup.party|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ohanameetup.party"] [uri "/xmlrpc.php"] [unique_id "aipOgqIxeZqbR5nuuvbkNwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-06-09 21:36:36
(3 days ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
Anonymous
2026-06-02 14:04:17
(1 week ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-02 13:33:42
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.41.104.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 45.41.104.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:33:35.829148 2026] [security2:error] [pid 15183:tid 15199] [client 45.41.104.232:37869] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.41.104.232 (+1 hits since last alert)|nimbll.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nimbll.com"] [uri "/xmlrpc.php"] [unique_id "ah7bryVi21dXmGJcWyxsbAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-21 15:33:52
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 45.41.104.232 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.41.104.232 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 21 10:33:41.944969 2025] [security2:error] [pid 18151:tid 18151] [client 45.41.104.232:12957] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||watermarks.info|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "watermarks.info"] [uri "/"] [unique_id "aUgTVU4RoSMoUz0l2_RvhwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-13 03:51:33
(5 months ago)
botnet
DDoS Attack
๐ซ๐ท
แดสแด
2025-07-30 08:29:32
(10 months ago)
Triggered Cloudflare WAF (firewallCustom) from MM.
ASN: 9988 (MPT-AP Myanma Posts and Telecommunicat ...
show more
Triggered Cloudflare WAF (firewallCustom) from MM.
ASN: 9988 (MPT-AP Myanma Posts and Telecommunications)
Protocol: HTTP/2 (GET method)
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
exxos
2025-07-23 01:03:18
(10 months ago)
Signup bot
Web Spam
๐ฆ๐บ
mielkan.com
2025-06-11 14:46:24
(1 year ago)
| blocked | mielkan-syd [443/tcp] | source port: 23279 | ttl: 41 | packet length: 60 | tos: 0x00 |
Port Scan
Web App Attack
๐ซ๐ท
Hiigara
2025-06-06 08:00:16
(1 year ago)
Blocked by firewall, multiple try
Port Scan
Brute-Force
Anonymous
2024-05-21 14:45:50
(2 years ago)
Automatic report - Vulnerability scan
/autodiscover/autodiscover.xml
Web App Attack
Anonymous
2024-04-15 16:18:37
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
ph
2024-02-15 02:46:43
(2 years ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
Anonymous
2022-11-12 21:31:58
(3 years ago)
Nov 13 03:31:57 ns3104219 postfix/smtpd[423]: NOQUEUE: reject: RCPT from unknown[45.41.104.232]: 450 ...
show more
Nov 13 03:31:57 ns3104219 postfix/smtpd[423]: NOQUEUE: reject: RCPT from unknown[45.41.104.232]: 450 4.7.1 Client host rejected: cannot find your reverse hostname, [45.41.104.232]; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<[45.41.104.232]>
...
show less
Email Spam
Web App Attack
๐ฉ๐ช
IP Analyzer
2022-09-21 14:01:21
(3 years ago)
Unauthorized connection attempt from IP address 45.41.104.232 on Port 445(SMB)
Port Scan