๐บ๐ธ
TPI-Abuse
2026-06-03 04:02:10
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 00:02:06.696154 2026] [security2:error] [pid 2100:tid 2100] [client 212.119.40.58:33127] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Cozzia/pics/Thumbs.db"] [unique_id "ah-nPsrACjdDTTFFvMOs_gAAAAo"], referer: https://vitalitywebb.com/backstore/Cozzia/pics/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 17:36:42
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 13:36:36.233846 2026] [security2:error] [pid 5470:tid 5470] [client 212.119.40.58:34997] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.anniversarymatchbooks.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.anniversarymatchbooks.com"] [uri "/s3cmd.ini"] [unique_id "afJBpHAY4qY9lNTcqGoVaAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-04-27 06:37:05
(1 month ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GE ...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (compatible; Konqueror/4.2; Linux) KHTML/4.2.4 (like Gecko) Slackware/13.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ญ
backslash
2025-06-19 21:05:08
(11 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2025-06-14 01:20:10
(11 months ago)
WAF: Block Joomla registration spam 2- wsit
Email Spam
Brute-Force
๐บ๐ธ
bluebrad
2025-05-22 15:37:00
(1 year ago)
Fake account
Web Spam
Email Spam
Spoofing
๐ฉ๐ช
Reinhard
2025-04-02 09:03:00
(1 year ago)
Msg from error-handling: Error: Illegal path. Body:Wed, 02 Apr 2025 11:03:48 +0200, IP-Addr:212.119. ...
show more
Msg from error-handling: Error: Illegal path. Body:Wed, 02 Apr 2025 11:03:48 +0200, IP-Addr:212.119.40.58, Host:212.119.40.58
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-05 10:03:11
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 05 05:03:02.198534 2025] [security2:error] [pid 41309:tid 41309] [client 212.119.40.58:42101] [client 212.119.40.58] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Ashebrooke 3056/Thumbs.db"] [unique_id "Z8ghVvIn1xCZC-5gmA2MBgAAAAE"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Ashebrooke%203056/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-21 00:20:11
(1 year ago)
This IP was involved in an brute force and password spray attack on 2024/10/20 19:13:27
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐ท๐บ
sms.ru
2024-09-30 07:20:05
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
๐จ๐ฆ
wil.com
2024-09-24 10:38:21
(1 year ago)
GlobalProtect login attempts with user lgibson.
VPN IP
Brute-Force
๐ต๐ฑ
sefinek.net
2024-09-01 12:01:38
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPhone; CPU iPhone OS 16_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3.1 Mobile/15E148 Safari/604.1 - en-US - https://www.twitch.tv/
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2024-09-01 12:01:38
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPhone; CPU iPhone OS 16_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3.1 Mobile/15E148 Safari/604.1 - en-US - https://www.twitch.tv/
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-08-27 09:44:54
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 212.119.40.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 27 05:44:49.418362 2024] [security2:error] [pid 2703719:tid 2703719] [client 212.119.40.58:13317] [client 212.119.40.58] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.accordionstars.com|F|2"] [data ".accordionfactory.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.accordionstars.com"] [uri "/www.accordionfactory.com"] [unique_id "Zs2gEUhoP1lplX35juBXQgAAAAw"], referer: http://www.accordionstars.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2024-08-09 18:03:12
(1 year ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot