Anonymous
2026-01-16 07:22:14
(4 months ago)
Aggressive Robot or Attack DDOS
DDoS Attack
π©πͺ
Didier Lagaert
2026-01-15 06:24:13
(4 months ago)
lie-88 : Bloc AI bots=>/(ai.)
Hacking
πΊπ¦
URAN Publishing Service
2026-01-14 13:47:36
(4 months ago)
74.7.227.53 - - [14/Jan/2026:15:47:33 +0200] "GET /wp-admin/js/index.php HTTP/1.1" 404 2859 "-" "Moz ...
show more
74.7.227.53 - - [14/Jan/2026:15:47:33 +0200] "GET /wp-admin/js/index.php HTTP/1.1" 404 2859 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
74.7.227.53 - - [14/Jan/2026:15:47:36 +0200] "GET /administrator/index.php HTTP/1.1" 404 218 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
...
show less
Web App Attack
π³π±
Site.eu
2026-01-14 01:15:22
(4 months ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
Vegascosmetics
2026-01-13 22:51:41
(4 months ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
π³π±
Site.eu
2026-01-12 09:13:52
(4 months ago)
Excessive multi-domain requests
Brute-Force
π³π±
Site.eu
2026-01-10 10:09:11
(4 months ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-01-07 04:31:15
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 23:31:09.301449 2026] [security2:error] [pid 19257:tid 19257] [client 74.7.227.53:33972] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.flashbackmusicmemories.com|F|2"] [data ".40svocaltrio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.flashbackmusicmemories.com"] [uri "/www.40svocaltrio.com"] [unique_id "aV3hjaWL5hqx96lPT3JergAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-07 03:15:19
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 22:15:15.748556 2026] [security2:error] [pid 16805:tid 16902] [client 74.7.227.53:52940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.seriousgames.global|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.seriousgames.global"] [uri "/events/caixias-do-sul-brasil/[email protected] "] [unique_id "aV3PwykNhDFy5VRkkzHtCgAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-06 10:06:15
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 05:06:12.726342 2026] [security2:error] [pid 26966:tid 26966] [client 74.7.227.53:34102] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rame-int.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rame-int.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aVzelKrHLX5Q-Ik0EON5eAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-01-04 12:47:37
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 74.7.227.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 07:47:32.093720 2026] [security2:error] [pid 14459:tid 14459] [client 74.7.227.53:41224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.smilingorc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.smilingorc.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aVphZATjWf-sosuH1gQvhgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
pinguin
2026-01-04 10:40:06
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¨π
backslash
2025-12-30 17:50:07
(5 months ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
π¦πΊ
MAGIC
2025-12-29 03:00:15
(5 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
π©πͺ
LRob.fr
2025-12-28 01:47:42
(5 months ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking