๐บ๐ธ
1gz
2026-10-03 06:10:44
(16 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /dayrui/Fcms/Readme.txt
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 14:58:14
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:58:05.217548 2026] [security2:error] [pid 26457:tid 26457] [client 240e:974:e801:11a:f2c::1e20:49136] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cottrillcyclodyne.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cottrillcyclodyne.com"] [uri "/okok.cer"] [unique_id "ar_GfZNTwP78TyYIroXeRwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-01 18:07:10
(2 days ago)
2026-10-01 20:05:30 AH01071: Got error 'Primary script unknown' && 2026-10-01 20:05:30 AH01071: Got ...
show more
2026-10-01 20:05:30 AH01071: Got error 'Primary script unknown' && 2026-10-01 20:05:30 AH01071: Got error 'Primary script unknown' && 2026-10-01 20:05:30 AH01071: Got error 'Primary script unknown' && 653 more within 20 minutes
show less
Web App Attack
Anonymous
2026-10-01 00:50:38
(2 days ago)
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:34 +0200] "GET /fun.php HTTP/1.1" 404 66091
240e: ...
show more
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:34 +0200] "GET /fun.php HTTP/1.1" 404 66091
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:34 +0200] "GET /logins.php HTTP/1.1" 404 66100
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:34 +0200] "GET /qqe.php HTTP/1.1" 404 66091
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:34 +0200] "GET /te.php HTTP/1.1" 404 66088
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:35 +0200] "GET /login8.php HTTP/1.1" 404 66100
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:35 +0200] "GET /login9.php HTTP/1.1" 404 66100
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:35 +0200] "GET /fun.php?ote?ote= HTTP/1.1" 404 66184
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:36 +0200] "GET /huyaa.php HTTP/1.1" 404 66097
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:37 +0200] "GET /wp-good.php HTTP/1.1" 404 61269
240e:974:e801:11a:f2c::1e20 - - [01/Oct/2026:02:50:37 +0200] "GET /X57.php HTTP/1.1" 404 61257
...
show less
Web Spam
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-28 20:20:15
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-28 20:13:41
(5 days ago)
240e:974:e801:11a:f2c::1e20 - - [28/Sep/2026:22:13:38 +0200] "GET /dayrui/Fcms/Readme.txt HTTP/1.1" ...
show more
240e:974:e801:11a:f2c::1e20 - - [28/Sep/2026:22:13:38 +0200] "GET /dayrui/Fcms/Readme.txt HTTP/1.1" 404 453 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:11a:f2c::1e20 - - [28/Sep/2026:22:13:38 +0200] "GET /shoppingcart.php HTTP/1.1" 404 577 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:11a:f2c::1e20 - - [28/Sep/2026:22:13:38 +0200] "GET /%E4%BD%BF%E7%94%A8%E8%AF%B4%E6%98%8E.txt HTTP/1.1" 404 453 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:11a:f2c::1e20 - - [28/Sep/2026:22:13:39 +0200] "GET / HTTP/1.1" 200 6659 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:11a:f2c::1e20 - - [28/Sep/2026:22:13:39 +0200] "GET /plus/img/df_dedetitle.gif HTTP/1.1" 40
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-28 13:30:23
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 09:30:18.155818 2026] [security2:error] [pid 1486:tid 1486] [client 240e:974:e801:11a:f2c::1e20:34740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||marianozaro.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marianozaro.com"] [uri "/okok.cer"] [unique_id "arpr6mMgwfbXD2MfG8gI2AAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:32:00
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:31:53.533949 2026] [security2:error] [pid 2036:tid 2036] [client 240e:974:e801:11a:f2c::1e20:39430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.mosherpit.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.mosherpit.com"] [uri "/okok.cer"] [unique_id "arpQKT8pjCO2HyoZKcdToAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 22:53:35
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 18:53:31.561884 2026] [security2:error] [pid 9772:tid 9808] [client 240e:974:e801:11a:f2c::1e20:51072] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kylight.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kylight.com"] [uri "/okok.cer"] [unique_id "armea2XU2AX5ZyJDrAA_LAAAAgc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 11:31:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 07:31:03.058111 2026] [security2:error] [pid 23930:tid 23950] [client 240e:974:e801:11a:f2c::1e20:38980] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deyyoungart.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deyyoungart.com"] [uri "/okok.cer"] [unique_id "arZbdzQzdhwONpjTgqOykAAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 22:38:45
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 18:38:39.547398 2026] [security2:error] [pid 27847:tid 27847] [client 240e:974:e801:11a:f2c::1e20:38726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidocchino.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidocchino.com"] [uri "/okok.cer"] [unique_id "arWmbwzJ2DDzNXsQ95mlhQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-09-24 21:10:00
(1 week ago)
IPBlock protected site ID [1438-do].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 20:16:15
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:16:07.722973 2026] [security2:error] [pid 19846:tid 19846] [client 240e:974:e801:11a:f2c::1e20:59658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||darrenj.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "darrenj.com"] [uri "/okok.cer"] [unique_id "arWFB2A5NOSW1cAjoGoeCAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:19:36
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:19:30.205177 2026] [security2:error] [pid 3523:tid 3523] [client 240e:974:e801:11a:f2c::1e20:59438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dandpcreamery.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dandpcreamery.com"] [uri "/okok.cer"] [unique_id "arVpsl-9Yb5i8Or8s_aBSAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:56:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:11a:f2c::1e20 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:56:05.772300 2026] [security2:error] [pid 1750:tid 1750] [client 240e:974:e801:11a:f2c::1e20:60072] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||namefinder.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "namefinder.com"] [uri "/okok.cer"] [unique_id "arQu1SF9Normqih_LJsFhAAAAAs"], referer: http://costaricacondos.com/okok.cer
show less
Brute-Force
Bad Web Bot
Web App Attack