๐บ๐ธ
TPI-Abuse
2026-10-01 01:45:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:45:34.285926 2026] [security2:error] [pid 2590:tid 2590] [client 162.158.155.43:11475] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nancybcatering.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nancybcatering.com"] [uri "/index.php.bak"] [unique_id "ar27PlRR3NJjFB4bfj67ngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 09:26:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 05:26:05.567783 2026] [security2:error] [pid 6240:tid 6265] [client 162.158.155.43:10364] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tkfay.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tkfay.com"] [uri "/index.php.bak"] [unique_id "arzVrT83WPi6zmTfTypxoAAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:07:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:07:13.361519 2026] [security2:error] [pid 3285:tid 3285] [client 162.158.155.43:13996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drwolberg.com"] [uri "/.htaccess"] [unique_id "arynEdu0yfa8B5FyU2XMqgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-29 10:59:17
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 07:49:03
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:48:59.052139 2026] [security2:error] [pid 1940:tid 2071] [client 162.158.155.43:10374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||financialcertified.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "financialcertified.com"] [uri "/index.php.bak"] [unique_id "artta-_Qt3QCbad2SWe3LgAAAkE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 07:21:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:21:14.386704 2026] [security2:error] [pid 27570:tid 27570] [client 162.158.155.43:11065] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atticlodgeoutdoorlearningcenter.com"] [uri "/.htaccess"] [unique_id "artm6lWFlb8PWk4MAmShzQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 21:42:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 17:42:30.454751 2026] [security2:error] [pid 15971:tid 15971] [client 162.158.155.43:12382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foxmm.com"] [uri "/wp-config.php"] [unique_id "arrfRt2bX_qfel9-RvZQTgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-03 22:01:46
(4 weeks ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
๐ง๐ช
madeit
2026-08-29 06:09:32
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:15:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:15:14.528070 2026] [security2:error] [pid 22617:tid 22617] [client 162.158.155.43:13121] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.paxbrewing.com"] [uri "/.git/config"] [unique_id "apAqUt2NmSV_yHWvRC3TtwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-08-24 23:36:02
(1 month ago)
This IP was detected by CrowdSec triggering custom/vpatch-bad-cloudflare.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 13:48:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:48:06.427764 2026] [security2:error] [pid 7537:tid 7537] [client 162.158.155.43:10196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sjhrc.org"] [uri "/.git/config"] [unique_id "aoxLlvvUrjQP_KEHfMSU4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
wiredalter
2026-05-16 23:10:41
(4 months ago)
Blocked by UFW on dVPS [2087/tcp]
Source Port: 13276
TTL: 50
Packet Length: 60
TOS: 0x00
Analyzed b ...
show more
Blocked by UFW on dVPS [2087/tcp]
Source Port: 13276
TTL: 50
Packet Length: 60
TOS: 0x00
Analyzed by https://ip.wiredalter.com
show less
Port Scan
Brute-Force
๐ฌ๐ง
pinguin
2026-04-06 02:04:38
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /https%3A/www.cloudflare.com/5xx-error-landing
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-20 08:50:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.155.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 04:50:41.205998 2026] [security2:error] [pid 12096:tid 12096] [client 162.158.155.43:10413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stansmarshservices.com"] [uri "/.env_backup"] [unique_id "ab0KYWLDxSNjoaAakb_Q3wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack