๐บ๐ธ
TPI-Abuse
2026-05-25 18:39:19
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 14:39:13.230149 2026] [security2:error] [pid 14436:tid 14436] [client 77.83.24.221:42519] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sunshinenv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sunshinenv.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahSXUSCxuniidzCTLL162gAAAAg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-11 05:59:36
(1 month ago)
(mod_security) mod_security (id:210350) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 01:59:30.999528 2026] [security2:error] [pid 1708916:tid 1708962] [client 77.83.24.221:13207] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||paidsearchconsulting.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "paidsearchconsulting.com"] [uri "/"] [unique_id "adnjQiQt-SaKCvdlQ7SVggAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-04-07 10:17:58
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST meth ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /wp-login.php
UA: curl/7.88.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Carsten
2026-03-27 06:06:08
(2 months ago)
Bad web bot [Apache-HttpClient/4.5.13 (Java/11.0.30)]
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-21 09:50:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 05:49:52.858022 2026] [security2:error] [pid 14185:tid 14185] [client 77.83.24.221:32067] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ncparanormalresearch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ncparanormalresearch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ab5pwNfvSiWrm8pnhcb13gAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-20 04:03:56
(2 months ago)
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:40 +0100] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Ap ...
show more
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:40 +0100] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:41 +0100] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:43 +0100] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:44 +0100] "POST /xmlrpc.php HTTP/1.1" 200 216 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:46 +0100] "POST /xmlrpc.php HTTP/1.1" 200 251 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:49 +0100] "POST /xmlrpc.php HTTP/1.1" 200 251 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 77.83.24.221 - - [20/Mar/2026:05:03:50 +0100] "POST /xmlrpc.php HTTP/1.1" 200 251 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 19:31:48
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 15:31:42.580871 2026] [security2:error] [pid 1688:tid 1688] [client 77.83.24.221:10367] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||harintonmechanical.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "harintonmechanical.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abhanr6Ltk0xLQSeRJSWVQAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-03-11 21:01:55
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-03-05 04:27:40
(3 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 360 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
masterguru
2026-03-05 03:49:54
(3 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 360 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ซ๐ท
masterguru
2026-02-23 15:19:06
(3 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 360 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ซ๐ท
masterguru
2026-02-21 10:43:38
(3 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 360 ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 77.83.24.221 (FI/Finland/-): 1 in the last 3600 secs (0-193)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-12-30 17:07:31
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 12:07:26.844609 2025] [security2:error] [pid 12888:tid 12888] [client 77.83.24.221:42443] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grandpont-house.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grandpont-house.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aVQGzknrCZq-g4ShQOh2pgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-09 05:08:21
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 77.83.24.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 00:08:15.282633 2025] [security2:error] [pid 21566:tid 21566] [client 77.83.24.221:45429] [client 77.83.24.221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koshland.org"] [uri "/.env"] [unique_id "Z80iPx1199ADbEfEiiYY_wAAAA0"], referer: https://tasamm.com/about/ggg235.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
sms.ru
2024-09-26 10:00:11
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack