๐บ๐ธ
mnsf
2025-06-09 21:05:24
(1 year ago)
Login Too Frequent (6)
Brute-Force
Web App Attack
๐ต๐ฑ
sefinek.net
2025-06-09 07:10:21
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /cms/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-06-09 06:16:16
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 02:16:08.416885 2025] [security2:error] [pid 2764962:tid 2764962] [client 45.61.149.2:49694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.birdlovesfish.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.birdlovesfish.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aEZ8KOljLq-t9Yk1HiBB6AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2025-06-09 04:10:16
(1 year ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-169)
Hacking
๐บ๐ธ
mnsf
2025-06-08 20:05:06
(1 year ago)
Login Too Frequent (6)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-08 02:44:15
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 07 22:44:10.769368 2025] [security2:error] [pid 501197:tid 501197] [client 45.61.149.2:50664] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nmorganist.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nmorganist.org"] [uri "/wordpress/wp-json/wp/v2/users/"] [unique_id "aET4-tWftiecKFI272mMLgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-08 00:56:10
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 07 20:56:07.031185 2025] [security2:error] [pid 3340176:tid 3340176] [client 45.61.149.2:57462] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharawi-gum.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aETfp4vyr0sMS7yKDjezGQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-08 00:26:21
(1 year ago)
attempts to hack passwords
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-07 23:57:48
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 07 19:57:41.638743 2025] [security2:error] [pid 3788289:tid 3788289] [client 45.61.149.2:51316] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||akistech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "akistech.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aETR9V8mINdn7HsvWxRdGAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-07 22:09:44
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 07 18:09:36.777724 2025] [security2:error] [pid 621908:tid 621908] [client 45.61.149.2:51112] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arriagarealestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arriagarealestate.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aES4oPvacp5am741CwMr3AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ManagedStack
2025-06-07 20:20:16
(1 year ago)
Wordpress Attack
Web App Attack
๐ฌ๐ง
Globe2
2025-06-07 19:43:13
(1 year ago)
[07/Jun/2025:20:43:11 +0100] 9tdNch4PgCmpmMFPA4tCZPop 45.61.149.2 64514 91.212.212.13 80
[07/Jun/202 ...
show more
[07/Jun/2025:20:43:11 +0100] 9tdNch4PgCmpmMFPA4tCZPop 45.61.149.2 64514 91.212.212.13 80
[07/Jun/2025:20:43:11 +0100] dGx0v4c00A04Jz5g-cnPLMwG 45.61.149.2 64514 91.212.212.13 80
[07/Jun/2025:20:43:12 +0100] E4JaaeN77ma009NgnLR6IqPm 45.61.149.2 64514 91.212.212.13 80
...
show less
Web App Attack
๐บ๐ธ
kosada.com
2025-06-07 18:31:32
(1 year ago)
Web vulnerability probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-05 16:10:52
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 45.61.149.2 (2.149.61.45.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 05 12:10:47.392289 2025] [security2:error] [pid 357985:tid 357985] [client 45.61.149.2:50890] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.edgebiopharma.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.edgebiopharma.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aEHBh8POFXNSvIeGVaT5YQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-06-04 20:20:01
(1 year ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack