๐ฉ๐ช
elm-st
2025-04-14 08:32:00
(1 year ago)
Multiple WAF violations
Brute-Force
Web App Attack
๐ฉ๐ช
Andreas Hiller
2025-04-12 06:00:07
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 8075 (MICROSOFT-CORP-MSN ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 8075 (MICROSOFT-CORP-MSN-AS-BLOCK)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-includes/css/alfa-rex.php
Timestamp: 2025-04-12T03:54:15Z
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-04-12 04:03:53
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 12 00:03:50.671097 2025] [security2:error] [pid 21467:tid 21467] [client 51.8.161.175:8506] [client 51.8.161.175] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||blc2.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "blc2.co"] [uri "/images/stories/admin-post.php"] [unique_id "Z_nmJtlHt9eOuA3SXZud4QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-04-12 04:00:08
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-04-12 03:36:16
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 23:36:11.665637 2025] [security2:error] [pid 26151:tid 26151] [client 51.8.161.175:1461] [client 51.8.161.175] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||bairentang.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "bairentang.org"] [uri "/images/stories/admin-post.php"] [unique_id "Z_nfqwQd0H1ClXD1TZe82wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-12 01:30:18
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 21:30:11.947908 2025] [security2:error] [pid 25808:tid 25808] [client 51.8.161.175:3231] [client 51.8.161.175] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||imerka.com.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "imerka.com.mx"] [uri "/images/stories/admin-post.php"] [unique_id "Z_nCI9Iq70nFjFElBYXo9QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jasperedv.de
2025-04-12 00:41:07
(1 year ago)
Apache Login - Brutforcing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-11 23:57:35
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 19:57:29.591860 2025] [security2:error] [pid 3080022:tid 3080022] [client 51.8.161.175:6609] [client 51.8.161.175] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "87"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||bradjohnsonqh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "bradjohnsonqh.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z_msad-KkhgnixKeL5aXpQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-11 23:27:47
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 19:27:40.379887 2025] [security2:error] [pid 8758:tid 8758] [client 51.8.161.175:7234] [client 51.8.161.175] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||jerusalem-korczak-home.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "jerusalem-korczak-home.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z_mlbDzSbSz-bLucx2gyRQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-04-11 23:15:25
(1 year ago)
[Sat Apr 12 01:15:25.108036 2025] [proxy_fcgi:error] [pid 1294187:tid 1294234] [remote 51.8.161.175: ...
show more
[Sat Apr 12 01:15:25.108036 2025] [proxy_fcgi:error] [pid 1294187:tid 1294234] [remote 51.8.161.175:0] AH01071: Got error 'Primary script unknown\n'
[Sat Apr 12 01:15:25.257750 2025] [proxy_fcgi:error] [pid 1294187:tid 1294230] [remote 51.8.161.175:0] AH01071: Got error 'Primary script unknown\n'
...
show less
Hacking
Web App Attack
Anonymous
2025-04-11 22:45:02
(1 year ago)
Bot / scanning and/or hacking attempts: GET /plugins/DaoZM.php HTTP/1.1, GET /wp-content/function.ph ...
show more
Bot / scanning and/or hacking attempts: GET /plugins/DaoZM.php HTTP/1.1, GET /wp-content/function.php HTTP/1.1, GET /wp-includes/SimplePie/system.php HTTP/1.1, GET /cgi-bin/1.php HTTP/1.1, GET /cgi-bin/admin.php HTTP/1.1, GET /.well-known/pki-validation/siteindex.php HTTP/1.1, GET /wp-admin/install.php HTTP/1.1, GET /wp-admin/network/lock.php HTTP/1.1, GET /assets/item.php HTTP/1.1, GET /wp-includes/style-engine/index.php HTTP/1.1, GET /db.php HTTP/1.1, GET /cgi-bin/about.php HTTP/1.1, GET /wp-content/plugins/pwnd/gecko.php HTTP/1.1, GET /wp-includes/sitemaps/alfa-rex.php HTTP/1.1, GET /Assets/admin.php HTTP/1.1, GET /install.php HTTP/1.1, GET /1.php HTTP/1.1, GET /about/wp-conflg.php HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-11 22:32:19
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 18:32:15.746386 2025] [security2:error] [pid 21406:tid 21406] [client 51.8.161.175:9133] [client 51.8.161.175] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||lunchboxhero.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "lunchboxhero.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z_mYb0w2ZcTMGB2GcTZ-7AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-11 21:31:55
(1 year ago)
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 51.8.161.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 11 17:31:51.202131 2025] [security2:error] [pid 3390049:tid 3390049] [client 51.8.161.175:7038] [client 51.8.161.175] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "87"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||wilburmanagementgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "wilburmanagementgroup.com"] [uri "/images/stories/admin-post.php"] [unique_id "Z_mKRxh_CUcb8ZkI8rqGNAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-04-11 21:28:45
(1 year ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-04-11 21:15:26
(1 year ago)
(WPLOGIN) WP Login Attack 51.8.161.175 (US/United States/-): 5 in the last 3600 secs; Ports: *; Dire ...
show more
(WPLOGIN) WP Login Attack 51.8.161.175 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack