๐บ๐ธ
TPI-Abuse
2026-02-04 20:15:30
(3 months ago)
(mod_security) mod_security (id:240000) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 04 15:15:21.480796 2026] [security2:error] [pid 28265:tid 28265] [client 212.30.36.90:29163] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||www.yankeetownfishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "www.yankeetownfishing.com"] [uri "/images/stories/themes.php"] [unique_id "aYOo2coEzkIrDIt6mvWgDQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-02-02 18:21:58
(4 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-02-02 02:05:06
(4 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-02-01 16:41:39
(4 months ago)
Multiple WAF Violations
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-01 00:32:48
(4 months ago)
IM360 WAF: Suspicious files in jQuery
Web App Attack
๐ฑ๐ป
garmtech.com
2026-02-01 00:32:19
(4 months ago)
IM360 WAF: Block access to the shell MV:/.wp/wso.php
Hacking
๐ซ๐ฎ
000rosiu
2026-01-28 21:53:49
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 137409 (GSLNETWORKS-AS-A ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: BLOCK
ASN: 137409 (GSLNETWORKS-AS-AP GSL Networks Pty LTD)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-content/plugins/backup-backup/includes/
Timestamp: 2026-01-28T21:46:19Z
Ray ID: 9c53ae8f1bc2dbe0
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36
Report generated by Cloudflare-WAF-To-AbuseIPDB:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
dynamix
2026-01-27 16:16:08
(4 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-01-23 17:28:01
(4 months ago)
wordpress-trap
Web App Attack
๐บ๐ธ
jcbriar
2026-01-19 11:02:56
(4 months ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-19 09:27:26
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 04:27:19.442693 2026] [security2:error] [pid 10170:tid 10170] [client 212.30.36.90:38823] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fingercult.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fingercult.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aW3490XpxojDaQgeFxKz7wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-19 08:24:39
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 03:24:31.867715 2026] [security2:error] [pid 14482:tid 14482] [client 212.30.36.90:32321] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||endoperfect.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "endoperfect.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aW3qPyC-7tPswrEJSyc1SQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-19 08:06:57
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 03:06:51.129976 2026] [security2:error] [pid 14103:tid 14103] [client 212.30.36.90:44371] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intra.es|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intra.es"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aW3mG4qaUHuBJnWtvBoeTwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-19 07:21:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 02:21:06.210071 2026] [security2:error] [pid 26722:tid 26722] [client 212.30.36.90:36661] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nickersoncarpentry.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nickersoncarpentry.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aW3bYp6X260DMZoU6ND_KgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-19 06:28:36
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.36.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 01:28:29.602439 2026] [security2:error] [pid 836:tid 836] [client 212.30.36.90:29937] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||starrmail.net|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "starrmail.net"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aW3PDTVWHIhLVsRXeXpjKwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack