π¬π·
setupgr
2026-07-30 01:07:36
(1 hour ago)
(wplogin_block) Blocked WP-Login Access Attempt 65.111.4.215 (US/United States/Virginia/Ashburn/-/[A ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 65.111.4.215 (US/United States/Virginia/Ashburn/-/[AS200373 DREI-K-TECH-GMBH]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 65.111.4.215 - - [30/Jul/2026:04:04:32 +0300] "POST /wp-login.php HTTP/1.1" 301 286 "https://doityourself.gr/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
show less
Port Scan
π«π·
ELYAZ
2026-07-29 11:52:44
(15 hours ago)
(wordpress) Failed wordpress login from 65.111.4.215 (US/United States/-): (CF_ENABLE)
Brute-Force
π©πͺ
raph
2026-06-26 02:05:10
(1 month ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-18 04:45:09
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π«π·
β¨
2026-04-21 23:33:14
(3 months ago)
Rule : Security
4 System %592 65.111.4.215 28149 ***hidden-privacy*** 80 6 248635872 %610 44
Port Scan
Hacking
Brute-Force
Anonymous
2026-03-04 22:12:52
(4 months ago)
Forum/form spam
Web Spam
π²πΉ
Malta
2026-01-01 14:14:38
(6 months ago)
65.111.4.215 - - [01/Jan/2026:15:14:38 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
65.111.4.215 - - [01/Jan/2026:15:14:38 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
show less
VPN IP
Hacking
Web App Attack
π©πͺ
Packets-Decreaser.NET
2025-12-29 14:00:57
(7 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
πΊπΈ
TPI-Abuse
2025-11-27 19:01:37
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 14:01:33.807564 2025] [security2:error] [pid 31034:tid 31034] [client 65.111.4.215:21773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acttapes.com"] [uri "/.git/HEAD"] [unique_id "aSigDRNN_nY60OfAf5jwWgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 07:46:42
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 02:46:32.926071 2025] [security2:error] [pid 1072:tid 1072] [client 65.111.4.215:50403] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.alessiaalessandra.com"] [uri "/.git/HEAD"] [unique_id "aSQNWI6AxhKqSppCE1m3owAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 06:04:48
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:04:42.321443 2025] [security2:error] [pid 22851:tid 22851] [client 65.111.4.215:21357] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allautousa.com"] [uri "/.git/HEAD"] [unique_id "aSP1euQkdiYCUgbRLru6JAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-24 04:36:56
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 65.111.4.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:36:42.533214 2025] [security2:error] [pid 15707:tid 15707] [client 65.111.4.215:60831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kamermanhome.com"] [uri "/.env"] [unique_id "aSPg2smPPJa7dPDJ2FfcAgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
sefinek.net
2025-11-16 11:10:35
(8 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /genshin-stella-mod
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 12_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 OPR/89.0.4447.51
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-11-14 17:05:12
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
π¦πΊ
AWW-Admin
2025-10-29 16:01:05
(9 months ago)
(wordpress) Failed wordpress login from 65.111.4.215 (US/United States/-)
Brute-Force