Anonymous
2025-07-23 06:03:21
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ต๐ฑ
sefinek.net
2025-05-22 02:58:20
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Vivaldi/5.3.2679.68
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-05-16 16:51:47
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 12:51:42.455701 2025] [security2:error] [pid 1177032:tid 1177032] [client 5.62.57.17:2345] [client 5.62.57.17] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.lowkeytiki.com|F|4"] [data "keep-alive, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.lowkeytiki.com"] [uri "/"] [unique_id "aCdtHlVkw6QdDZgrquVw4wAAABU"], referer: http://www.lowkeytiki.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-16 14:22:35
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 10:22:30.950590 2025] [security2:error] [pid 3011238:tid 3011249] [client 5.62.57.17:1498] [client 5.62.57.17] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||oceanstatecollision.com|F|4"] [data "keep-alive, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "oceanstatecollision.com"] [uri "/"] [unique_id "aCdKJnqA3IVRzZy9rR9CFwAAAIk"], referer: http://oceanstatecollision.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-16 12:31:20
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 08:31:15.713428 2025] [security2:error] [pid 752165:tid 752165] [client 5.62.57.17:2044] [client 5.62.57.17] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||tristarus.com|F|4"] [data "keep-alive, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tristarus.com"] [uri "/"] [unique_id "aCcwExAUe7Lo_BdX6Y7CXAAAAA4"], referer: https://tristarus.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-03 17:56:53
(1 year ago)
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 03 13:56:48.694783 2025] [security2:error] [pid 3085462:tid 3085462] [client 5.62.57.17:1296] [client 5.62.57.17] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.heavenonearthonline.net|F|4"] [data "keep-alive, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.heavenonearthonline.net"] [uri "/"] [unique_id "aBZY4Brj53y6LL18UsGF5gAAABQ"], referer: http://www.heavenonearthonline.net
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-31 16:59:33
(1 year ago)
Malicious activity detected
Hacking
Web App Attack
๐ช๐ธ
10dencehispahard SL
2025-03-04 21:00:55
(1 year ago)
Unauthorized login attempts [ apache-4xx]
Brute-Force
๐บ๐ธ
octageeks.com
2025-02-06 05:07:57
(1 year ago)
Wordpress malicious attack:[octa404]
Web App Attack
Anonymous
2024-12-26 05:41:29
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
fortypoundhead
2024-08-13 20:51:56
(2 years ago)
SQL Injection Attempt
SQL Injection
Web App Attack
๐ง๐ช
cmbplf
2024-08-13 04:21:41
(2 years ago)
679 requests to */xmlrpc.php
Brute-Force
Bad Web Bot
๐จ๐ฆ
KIsmay
2024-08-13 04:05:37
(2 years ago)
Aug 13 00:05:33 www4 WPAudit[1862507]: 5.62.57.17 www.vhsport.ca "Mozilla/5.0 (Windows NT 10.0; Win6 ...
show more
Aug 13 00:05:33 www4 WPAudit[1862507]: 5.62.57.17 www.vhsport.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" vhsport:2019 FAIL
Aug 13 00:05:34 www4 WPAudit[1862507]: 5.62.57.17 www.vhsport.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" vhsport:202020 FAIL
Aug 13 00:05:35 www4 WPAudit[1862507]: 5.62.57.17 www.vhsport.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" vhsport:210877 FAIL
Aug 13 00:05:36 www4 WPAudit[1862507]: 5.62.57.17 www.vhsport.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" vhsport:2112 FAIL
Aug 13 00:05:37 www4 WPAudit[1862507]: 5.62.57.17 www.vhsport.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36" vhsport:212121 FAIL
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-17 10:31:20
(2 years ago)
(mod_security) mod_security (id:225170) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 5.62.57.17 (r-17-57-62-5.consumer-pool.prcdn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 17 06:31:13.695688 2024] [security2:error] [pid 26318] [client 5.62.57.17:2111] [client 5.62.57.17] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||salsberggroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "salsberggroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZnAQcZ8zJiKcvi_SezdN3gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-04-08 11:08:10
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot