🇺🇸
TPI-Abuse
2026-09-12 15:18:42
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:18:36.055556 2026] [security2:error] [pid 14653:tid 14653] [client 120.55.194.1:50000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||afdfurniture.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "afdfurniture.com"] [uri "/okok.cer"] [unique_id "aqVtTLLYbdZTkaSTU4l15wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:39:17
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:39:12.563875 2026] [security2:error] [pid 31455:tid 31455] [client 120.55.194.1:47572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||acmax.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "acmax.com"] [uri "/okok.cer"] [unique_id "aqRY4BY7yq0mrXG0exjtcgAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:50:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:50:35.854305 2026] [security2:error] [pid 19794:tid 19807] [client 120.55.194.1:52438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aceelectricalsupplies.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aceelectricalsupplies.com"] [uri "/okok.cer"] [unique_id "aqQ_awSvoQAMIFX0zcCUAAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 17:16:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 120.55.194.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:16:49.583451 2026] [security2:error] [pid 27345:tid 27345] [client 120.55.194.1:50874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||accsbg.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "accsbg.org"] [uri "/okok.cer"] [unique_id "aqQ3gRlvlQMdpXmjxk9_XgAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2026-09-05 11:13:29
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /static/warn/close.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇬🇧
consul.to
2026-09-05 08:14:28
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
IRISIO
2026-09-04 13:13:06
(1 week ago)
scans/SQL injection/spam posts : 129 queries
Web App Attack
SQL Injection
Anonymous
2026-09-04 09:36:42
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇮🇹
ciccio diddo
2026-09-04 08:00:29
(1 week ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇬🇧
CrystalMaker
2026-09-02 23:26:10
(1 week ago)
PHP vulnerability scan - GET /static/warn/close.php; GET /README.md; GET /miniprogram/code/default_b ...
show more
PHP vulnerability scan - GET /static/warn/close.php; GET /README.md; GET /miniprogram/code/default_baidu/app.js
show less
Web App Attack
Anonymous
2026-09-02 16:40:38
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
ambor
2026-08-27 08:35:24
(2 weeks ago)
Honeypot access: PHP file scan attempt: /static/warn/close.php. Path: /static/warn/close.php
Web App Attack
🇮🇹
VHosting
2026-08-21 11:00:09
(3 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack