๐บ๐ธ
TPI-Abuse
2025-09-01 19:42:48
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 15:42:43.298772 2025] [security2:error] [pid 2859:tid 2859] [client 45.91.20.220:49843] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brazilianbikinis.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brazilianbikinis.com"] [uri "/bak/backup.sql"] [unique_id "aLX3M4CF-rBGavagREeYvwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2025-08-29 22:02:41
(1 year ago)
2 attack(s) detected since 2025-08-29T21:48:06.170Z, such as these: {"event":"nginx_block","ip":"45. ...
show more
2 attack(s) detected since 2025-08-29T21:48:06.170Z, such as these: {"event":"nginx_block","ip":"45.91.20.220","host":"p4u.xyz","request":"HEAD /back/public_html.tar.gz HTTP/2.0","user_agent":"","reason":"404","timestamp":"2025-08-29T21:48:11 00:00"} More Details: https://p4u.xyz/0A7NVMCEIPS/1
show less
Web Spam
Hacking
Bad Web Bot
๐ฌ๐ง
pinguin
2025-08-27 08:50:40
(1 year ago)
Triggered Cloudflare WAF (firewallManaged) from IT.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from IT.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /bak/www.zip
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-23 22:16:01
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 23 18:15:56.211161 2025] [security2:error] [pid 24306:tid 24306] [client 45.91.20.220:35061] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hodlmoser.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hodlmoser.com"] [uri "/restore/wallet.dat"] [unique_id "aKo9nKD5OWxBf3ML_BJtewAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2025-08-21 01:57:50
(1 year ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-08-19 14:12:01
(1 year ago)
WP Admin Scan Activities
Web App Attack
๐ธ๐ฌ
pusathosting.com
2025-08-19 08:54:04
(1 year ago)
2ds22 bruteforce
Brute-Force
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-08-19 02:55:48
(1 year ago)
WP Admin Scan Activities
Web App Attack
๐บ๐ธ
CBJ
2025-08-18 20:29:43
(1 year ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-08-18 18:44:26
(1 year ago)
45.91.20.220 - - [18/Aug/2025:21:44:23 +0300] "GET //wp-includes/blocks/page-list/page-list/index.ph ...
show more
45.91.20.220 - - [18/Aug/2025:21:44:23 +0300] "GET //wp-includes/blocks/page-list/page-list/index.php HTTP/1.1" 404 274 "-" "Go-http-client/1.1"
45.91.20.220 - - [18/Aug/2025:21:44:25 +0300] "GET //wp-admin/includes/nav.php HTTP/1.1" 404 274 "-" "Go-http-client/1.1"
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2025-08-18 15:35:40
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.91.20.220 (IT/Italy/-): 1 in the ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.91.20.220 (IT/Italy/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-04 08:51:29
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 04 04:51:21.988276 2025] [security2:error] [pid 345:tid 345] [client 45.91.20.220:25715] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thegoldentether.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thegoldentether.com"] [uri "/old/backup.sql"] [unique_id "aJB0iX4umofwUF49FMONlwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-03 09:56:13
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 05:56:08.731702 2025] [security2:error] [pid 24825:tid 24825] [client 45.91.20.220:54907] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robcohn.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robcohn.com"] [uri "/restore/sql.sql"] [unique_id "aI8yOMkiZewPRY1EoYoFQQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-24 16:02:14
(1 year ago)
Web attack
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-20 02:51:57
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.91.20.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 19 22:51:53.655428 2025] [security2:error] [pid 5236:tid 5236] [client 45.91.20.220:44115] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wendeenicole.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wendeenicole.com"] [uri "/back/backup.sql"] [unique_id "aHxZycxYt8UoCzrbPuuxbAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack