๐บ๐ธ
TPI-Abuse
2026-06-16 21:21:29
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 17:21:22.282813 2026] [security2:error] [pid 27115:tid 27115] [client 2a03:2880:13ff:1:::40942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.phantomkennels.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.phantomkennels.com"] [uri "/[email protected] "] [unique_id "ajG-Utq-RhPcZeLFarhDXwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 02:10:20
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 22:10:14.958124 2026] [security2:error] [pid 13388:tid 13388] [client 2a03:2880:13ff:1:::33874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "aitqhndnKCweULu2AQsKKQAAAAY"], referer: https://civilwarzone.com/March.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 18:54:01
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 14:53:53.406758 2026] [security2:error] [pid 22267:tid 22267] [client 2a03:2880:13ff:1:::57862] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.phantomkennels.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.phantomkennels.com"] [uri "/[email protected] "] [unique_id "ahngwSS8UyBKVRMAdEpFkgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Penny Packer
2026-03-25 08:27:26
(2 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฉ๐ช
conseilgouz
2026-03-23 20:36:19
(2 months ago)
ece-88 : Bloc AI bots=>/robots.txt(facebookexternalhit)
Hacking
๐ณ๐ฑ
i-turnradio.nl
2026-03-19 11:34:33
(3 months ago)
2026-03-19 12:34:32 (CET) ~ Blocked by abusescan risk assessment
Web App Attack
๐ซ๐ท
mrcrassi
2026-03-18 15:38:17
(3 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produtos
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
ambor
2026-03-16 10:27:50
(3 months ago)
Attack type: wordpress_attack_attempt | Target: /robots.txt | UA: facebookexternalhit/1.1 (+http://w ...
show more
Attack type: wordpress_attack_attempt | Target: /robots.txt | UA: facebookexternalhit/1.1 (+http://www.facebook.com/ | Country: US
show less
Web App Attack
Brute-Force
๐ซ๐ท
conseilgouz
2026-03-16 09:57:54
(3 months ago)
sae-88 : Bloc AI bots=>/(facebookexternalhit)
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-15 21:55:23
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:13ff:1:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 17:55:20.057060 2026] [security2:error] [pid 21509:tid 21509] [client 2a03:2880:13ff:1:::50118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.phantomkennels.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.phantomkennels.com"] [uri "/[email protected] "] [unique_id "abcqyH6tKgosSefpRYGLDwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-03-10 09:44:38
(3 months ago)
vee-Security key failure(facebookexternalhit)
Hacking
๐ซ๐ท
conseilgouz
2026-03-09 09:16:35
(3 months ago)
sae-88 : Bloc AI bots=>/(facebookexternalhit)
Hacking
๐บ๐ธ
mawan
2026-03-05 05:44:39
(3 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
Penny Packer
2026-03-03 23:09:16
(3 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ธ๐ฌ
mypatricks
2026-02-28 02:40:05
(3 months ago)
2a03:2880:13ff:1::/242.114.2.74 | Port: 13732 | DNS: 2a03:2880:13ff:1:: 2026-02-28T10:40:04+08:00 Am ...
show more
2a03:2880:13ff:1::/242.114.2.74 | Port: 13732 | DNS: 2a03:2880:13ff:1:: 2026-02-28T10:40:04+08:00 America/Chicago | Un-authorized bots or crawlers | UA: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler) HTTP/1.1 443 GET | URL: / | Ref: - | Country: US/United States/-08:00 IP City: Springfield 9d4c8e16ee65676d-DFW/Dallas, TX, United States 1 hits/0 secs Robots 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host