Anonymous
2026-06-14 17:16:22
(1 day ago)
Web App Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 07:01:14
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 172.69.130.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.130.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 03:01:11.311959 2026] [security2:error] [pid 25532:tid 25532] [client 172.69.130.252:9524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.directcch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.directcch.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ai5Rt8DE4SjBOSwNvoFywgAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-06-11 04:10:49
(4 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 19:57:27
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 172.69.130.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.130.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 15:57:24.455038 2026] [security2:error] [pid 1230:tid 1230] [client 172.69.130.252:11070] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.photoboutiqueamerica.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.photoboutiqueamerica.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ainBpBo-EZLSnWHHGQQZiAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 09:43:24
(1 week ago)
[Wed Jun 03 11:43:23.155708 2026] [authz_core:error] [pid 27237] [client 172.69.130.252:13480] AH016 ...
show more
[Wed Jun 03 11:43:23.155708 2026] [authz_core:error] [pid 27237] [client 172.69.130.252:13480] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Jun 03 11:43:23.282949 2026] [authz_core:error] [pid 27237] [client 172.69.130.252:13480] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Wed Jun 03 11:43:23.420481 2026] [authz_core:error] [pid 27237] [client 172.69.130.252:13480] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-06-01 05:55:48
(2 weeks ago)
[Mon Jun 01 07:55:46.984112 2026] [authz_core:error] [pid 9255] [client 172.69.130.252:13299] AH0163 ...
show more
[Mon Jun 01 07:55:46.984112 2026] [authz_core:error] [pid 9255] [client 172.69.130.252:13299] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 01 07:55:47.002761 2026] [authz_core:error] [pid 9271] [client 172.69.130.252:13307] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Mon Jun 01 07:55:47.011685 2026] [authz_core:error] [pid 9272] [client 172.69.130.252:13301] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-05-31 12:49:37
(2 weeks ago)
Aggressive web scan
Web App Attack
Anonymous
2026-05-29 19:50:48
(2 weeks ago)
[Fri May 29 21:50:28.730594 2026] [authz_core:error] [pid 6299] [client 172.69.130.252:13094] AH0163 ...
show more
[Fri May 29 21:50:28.730594 2026] [authz_core:error] [pid 6299] [client 172.69.130.252:13094] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 29 21:50:47.854924 2026] [authz_core:error] [pid 6300] [client 172.69.130.252:13010] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Fri May 29 21:50:48.015247 2026] [authz_core:error] [pid 6300] [client 172.69.130.252:13010] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π©πͺ
abdubhai
2026-05-29 11:15:53
(2 weeks ago)
172.69.130.252 - - [29/May/2026:
...
Brute-Force
Anonymous
2026-05-28 00:32:44
(2 weeks ago)
[Thu May 28 02:32:43.070842 2026] [authz_core:error] [pid 24392] [client 172.69.130.252:10181] AH016 ...
show more
[Thu May 28 02:32:43.070842 2026] [authz_core:error] [pid 24392] [client 172.69.130.252:10181] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu May 28 02:32:43.637278 2026] [authz_core:error] [pid 24392] [client 172.69.130.252:10181] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu May 28 02:32:43.974651 2026] [authz_core:error] [pid 24392] [client 172.69.130.252:10181] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
π¬π§
pinguin
2026-05-25 21:32:44
(2 weeks ago)
Triggered Cloudflare WAF (linkMaze) from CA.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF (linkMaze) from CA.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/2 (GET method)
Endpoint: /NewFile.php
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-05-23 20:59:26
(3 weeks ago)
[Sat May 23 22:59:24.223375 2026] [authz_core:error] [pid 14683] [client 172.69.130.252:9313] AH0163 ...
show more
[Sat May 23 22:59:24.223375 2026] [authz_core:error] [pid 14683] [client 172.69.130.252:9313] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 23 22:59:24.905324 2026] [authz_core:error] [pid 14683] [client 172.69.130.252:9313] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 23 22:59:25.334276 2026] [authz_core:error] [pid 14683] [client 172.69.130.252:9313] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-05-22 21:22:43
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-19 18:10:33
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.69.130.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.69.130.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 14:10:27.952390 2026] [security2:error] [pid 891:tid 891] [client 172.69.130.252:9396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.photoboutiqueamerica.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.photoboutiqueamerica.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "agynk1PIHJX8UdY9DfSrzQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
F242
2026-05-16 00:25:29
(4 weeks ago)
Wordpress Login or XMLRPC abuse
Web App Attack