๐บ๐ธ
TPI-Abuse
2026-06-14 06:52:59
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:52:51.257206 2026] [security2:error] [pid 6688:tid 6688] [client 172.70.50.107:9831] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.asurprisinglittletown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.asurprisinglittletown.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ai5Pw6vrDGC89ySOnj3m-AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-06-14 00:37:31
(19 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 21:39:37
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 17:39:31.022063 2026] [security2:error] [pid 19990:tid 20034] [client 172.70.50.107:14206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.tristatepropertymgmt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.tristatepropertymgmt.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "aiiIEw7JIxwWZXbxIVUvOQAAAY8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
gonet.home
2026-05-30 00:30:07
(2 weeks ago)
Security Event Detected by SOC Gonet: event=alert, hits=2
Brute-Force
๐ฎ๐ฉ
gonet.home
2026-05-29 00:26:57
(2 weeks ago)
Security Event Detected by SOC Gonet: event=alert, hits=2
Brute-Force
๐ฎ๐ฉ
gonet.home
2026-05-27 10:15:05
(2 weeks ago)
Security Event Detected by SOC Gonet: event=alert, hits=2
Brute-Force
๐ฎ๐ฉ
gonet.home
2026-05-26 10:15:04
(2 weeks ago)
Security Event Detected by SOC Gonet: event=alert, hits=2
Brute-Force
๐ฎ๐ฉ
gonet.home
2026-05-25 10:10:05
(2 weeks ago)
Security Event Detected by SOC Gonet: event=alert, hits=2
Brute-Force
๐ฉ๐ช
srtzero
2026-05-25 01:51:36
(2 weeks ago)
172.70.50.107 - - [25/May/2026:03:51:35 +0200] "GET /wp-includes/ID3/about.php HTTP/1.1" 404 118 "-" ...
show more
172.70.50.107 - - [25/May/2026:03:51:35 +0200] "GET /wp-includes/ID3/about.php HTTP/1.1" 404 118 "-" "-"
172.70.50.107 - - [25/May/2026:03:51:35 +0200] "GET /wp-admin/css/ HTTP/1.1" 404 118 "-" "-"
172.70.50.107 - - [25/May/2026:03:51:35 +0200] "GET /wp-admin/css/colors/modern/ HTTP/1.1" 404 118 "-" "-"
...
show less
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-05-23 22:53:42
(3 weeks ago)
Web App Attack
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2026-05-15 03:22:11
(4 weeks ago)
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
...
show more
Triggered Cloudflare WAF (firewallManaged) from CA.
Action taken: LOG
Protocol: HTTP/2 (GET method)
Endpoint: /wp-json/gravitysmtp/v1/tests/mock-data
UA: curl/8.7.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-08 15:31:21
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 11:31:14.323521 2026] [security2:error] [pid 2724854:tid 2724854] [client 172.70.50.107:9224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ktnwassociatesinc.com"] [uri "/.env.staging"] [unique_id "adZ0wkfBikp5JTJv6sKDTgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 23:27:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 19:26:51.964344 2026] [security2:error] [pid 599949:tid 599949] [client 172.70.50.107:10804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/.env.dev"] [unique_id "adRBO99axySoLwwzxRsccgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 17:45:42
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 13:45:35.355496 2026] [security2:error] [pid 264003:tid 264003] [client 172.70.50.107:11105] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.fatlandtheplay.com"] [uri "/.env_backup"] [unique_id "adPxPxYKKUQjKwV4AQPpJgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 08:23:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.50.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 04:23:07.801939 2026] [security2:error] [pid 23912:tid 23912] [client 172.70.50.107:13386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.reneehill.net"] [uri "/.env.development"] [unique_id "adNtazXGtv-H8iGszHq2TQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack