๐จ๐ฟ
SystemAdmin
2026-08-21 15:27:36
(1 week ago)
Doing bad things...
Web App Attack
Anonymous
2025-11-03 10:38:48
(9 months ago)
wordpress-trap
Web App Attack
Anonymous
2025-11-03 07:53:13
(9 months ago)
wordpress-trap
Web App Attack
Anonymous
2025-11-02 08:18:22
(9 months ago)
wordpress-trap
Web App Attack
Anonymous
2025-11-01 23:01:31
(9 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-31 22:11:03
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 31 18:10:56.967654 2025] [security2:error] [pid 16223:tid 16223] [client 95.164.145.180:31029] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fashionmenswear.com|F|2"] [data ".old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fashionmenswear.com"] [uri "/backup.old"] [unique_id "aQUz8AmnltnPLBHc8dLO1AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2025-10-30 17:34:37
(9 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-30 06:55:23
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 02:55:15.526273 2025] [security2:error] [pid 31264:tid 31264] [client 95.164.145.180:52089] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-delaware.com"] [uri "/wp-config.php~"] [unique_id "aQML00pE3kscZvNWraC_awAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-29 18:23:53
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 14:23:49.598430 2025] [security2:error] [pid 19428:tid 19428] [client 95.164.145.180:41423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kalvannastudios.com"] [uri "/wp-content/uploads/wp-config.php.bak"] [unique_id "aQJbtQI1e_khjwstq5apdQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
Shaik Sai Meera
2025-10-28 17:37:58
(10 months ago)
IM360 WAF: RBL Dirb like fuzzing
Brute-Force
๐ซ๐ท
mrcrassi
2025-10-27 06:36:22
(10 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /backup/wp-config.php.old
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:135.0) Gecko/20100101 Firefox/135.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-27 00:56:52
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 26 20:56:46.802448 2025] [security2:error] [pid 28260:tid 28260] [client 95.164.145.180:41355] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bergopro.co.uk"] [uri "/backup/wp-config.php.bak"] [unique_id "aP7DTpNYQ5YBCkYWTkOYqAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-27 00:49:04
(10 months ago)
(php_susp_dir) srv102 PHP in suspicious dir 95.164.145.180 (US/United States/-): 1 in the last 3600 ...
show more
(php_susp_dir) srv102 PHP in suspicious dir 95.164.145.180 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-27 00:01:24
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 26 20:01:18.734855 2025] [security2:error] [pid 4823:tid 4823] [client 95.164.145.180:25099] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cier.xyz|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cier.xyz"] [uri "/backup/wp-config.php.bak"] [unique_id "aP62TnYK6l1Gjx9MjehmrgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-26 21:54:40
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 95.164.145.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 26 17:54:33.864776 2025] [security2:error] [pid 10940:tid 10940] [client 95.164.145.180:1899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krystalsgiftshopandboutique.net"] [uri "/backup/wp-config.php.bak"] [unique_id "aP6YmamQQl9gh36PRHK0eAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack