๐บ๐ธ
TPI-Abuse
2026-09-04 17:23:21
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 13:23:14.391761 2026] [security2:error] [pid 8292:tid 8292] [client 2a03:2880:f800:42:::55754] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.shorelineshowerdoor.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.shorelineshowerdoor.com"] [uri "/shorelineshowerdoor.com"] [unique_id "apr-gqfHwNV9IkxahoY4HQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-04 01:23:32
(1 day ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 13:48:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:48:20.139775 2026] [security2:error] [pid 1689:tid 1689] [client 2a03:2880:f800:42:::63928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hakkawok.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hakkawok.com"] [uri "/hakkawok.com"] [unique_id "apl6pPCQkZvqFjfVzxfq3QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 04:13:05
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:12:59.529531 2026] [security2:error] [pid 22821:tid 22821] [client 2a03:2880:f800:42:::37848] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||go-901.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "go-901.com"] [uri "/go-901.com"] [unique_id "apjzy1lIGj0LyMGCYAjPagAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 02:17:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 22:17:47.653695 2026] [security2:error] [pid 16371:tid 16371] [client 2a03:2880:f800:42:::54936] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wallawallafirearmstraining.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wallawallafirearmstraining.com"] [uri "/wallawallafirearmstraining.com"] [unique_id "apjYy38T-29krAuuin83SAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-09-02 19:53:59
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /booru | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
Skyrider
2026-09-02 14:36:03
(2 days ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-02 04:53:43
(3 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:24:35
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:949110) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:24:30.320912 2026] [security2:error] [pid 19780:tid 19780] [client 2a03:2880:f800:42:::23116] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "krupaandsons.com"] [uri "/krupaandsons.com"] [unique_id "apdQnrGB9YVzXiFd4zJ19gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:38:57
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:38:49.704156 2026] [security2:error] [pid 21317:tid 21317] [client 2a03:2880:f800:42:::49860] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "apbVadt8ChrmbXVE6ATwaQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
relianoid.com
2026-08-30 13:18:56
(5 days ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 10:02:33
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 06:02:26.353740 2026] [security2:error] [pid 4510:tid 4510] [client 2a03:2880:f800:42:::43704] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vc1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vc1.com"] [uri "/vc1.com"] [unique_id "apP_srGpvEb82YeBvTbLjAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
abuseipdb.amaze321
2026-08-29 06:40:19
(1 week ago)
Automated reconnaissance: repeated requests for sensitive/non-existent paths.
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 20:18:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:17:54.848432 2026] [security2:error] [pid 10074:tid 10074] [client 2a03:2880:f800:42:::22750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elearning.nextngnr.com"] [uri "/8IB1Qb.htaccess"] [unique_id "apHs8oDnRWHTGAJqB6XmCQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:06:36
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f800:42:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:06:30.048775 2026] [security2:error] [pid 5019:tid 5019] [client 2a03:2880:f800:42:::41142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoretopicturenetwork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoretopicturenetwork.com"] [uri "/scoretopicturenetwork.com"] [unique_id "apDC9n0SGcTOSJvaUaKPdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack