๐ซ๐ท
mrcrassi
2026-03-30 12:47:42
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: curl/7.88.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
oralunal
2026-03-17 19:57:20
(2 months ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
Anonymous
2026-01-06 14:43:29
(5 months ago)
Forum/form spam
Web Spam
Anonymous
2025-11-18 20:53:16
(6 months ago)
wordpress-trap
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-17 22:40:30
(6 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-40.45.80.107.231.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-40.45.80.107.231.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-12 07:34:48
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 45.80.107.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.80.107.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 12 03:34:41.190448 2025] [security2:error] [pid 640:tid 640] [client 45.80.107.231:25415] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sydneysue.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sydneysue.com"] [uri "/"] [unique_id "aOtaEcmkiE_wfC9TeKLGEgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-22 07:48:08
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 45.80.107.231 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.80.107.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 22 03:48:03.939814 2025] [security2:error] [pid 31270:tid 31270] [client 45.80.107.231:30057] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||powerastronomy.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "powerastronomy.com"] [uri "/"] [unique_id "aND_MyQanxMTKarzK-_F9AAAAAA"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Soapy7261
2025-01-21 01:09:19
(1 year ago)
HTTP Method: GET | Tried to access: /.env.production --- This report is automated ---
Brute-Force
Web App Attack
๐ต๐ฑ
nfsec.pl
2025-01-19 22:13:00
(1 year ago)
45.80.107.231 - - [19/Jan/2025:23:12:50 +0100] "GET /.env HTTP/1.1" 403 387 "-" "Mozilla/5.0"
45.80. ...
show more
45.80.107.231 - - [19/Jan/2025:23:12:50 +0100] "GET /.env HTTP/1.1" 403 387 "-" "Mozilla/5.0"
45.80.107.231 - - [19/Jan/2025:23:12:52 +0100] "GET /config/.env HTTP/1.1" 403 387 "-" "Mozilla/5.0"
45.80.107.231 - - [19/Jan/2025:23:12:55 +0100] "GET /.env.dev HTTP/1.1" 403 387 "-" "Mozilla/5.0"
45.80.107.231 - - [19/Jan/2025:23:12:58 +0100] "GET /www/.env HTTP/1.1" 403 387 "-" "Mozilla/5.0"
45.80.107.231 - - [19/Jan/2025:23:13:00 +0100] "GET /flask/.env HTTP/1.1" 403 387 "-" "Mozilla/5.0"
...
show less
Exploited Host
Web App Attack
Anonymous
2025-01-17 09:53:56
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ฆ
wil.com
2024-06-15 20:23:04
(1 year ago)
GlobalProtect login attempts with user ejones.
VPN IP
Brute-Force
Anonymous
2024-05-25 00:59:54
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-03-10 01:14:44
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH