๐บ๐ธ
TPI-Abuse
2025-12-11 03:43:32
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 22:43:29.937502 2025] [security2:error] [pid 8189:tid 8189] [client 2a03:2880:f806:13:::36778] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vc1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vc1.com"] [uri "/vc1.com"] [unique_id "aTo94XaOvDLQx_cyX_eVcAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 03:58:44
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 22:58:37.908108 2025] [security2:error] [pid 25084:tid 25084] [client 2a03:2880:f806:13:::45668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jennlaurenphotography.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jennlaurenphotography.com"] [uri "/jennlaurenphotography.com"] [unique_id "aTeebSJyY2CMJdUvCtQCUwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 03:20:40
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 22:20:32.775467 2025] [security2:error] [pid 12054:tid 12054] [client 2a03:2880:f806:13:::48710] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "aTeVgME2NDNuF2E7EWu3xwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 03:05:04
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 22:04:58.786562 2025] [security2:error] [pid 16306:tid 16306] [client 2a03:2880:f806:13:::46584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "aTeR2m9GoA9eot2wAj0P0gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-04 00:38:18
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 03 19:38:10.419678 2025] [security2:error] [pid 26942:tid 26942] [client 2a03:2880:f806:13:::55782] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||napaautopartskeokuk.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "napaautopartskeokuk.com"] [uri "/napaautopartskeokuk.com"] [unique_id "aTDX8hvM2U2HZBswQu7-XAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-03 12:43:19
(9 months ago)
[Wed Dec 03 13:42:55.047517 2025] [authz_core:error] [pid 2471345:tid 2748102] [remote 2a03:2880:f80 ...
show more
[Wed Dec 03 13:42:55.047517 2025] [authz_core:error] [pid 2471345:tid 2748102] [remote 2a03:2880:f806:13:::58478] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:43:10.069384 2025] [authz_core:error] [pid 2471489:tid 2471492] [remote 2a03:2880:f806:13:::50798] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:43:18.686618 2025] [authz_core:error] [pid 2471345:tid 2471356] [remote 2a03:2880:f806:13:::39426] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 23:45:37
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 18:45:34.983880 2025] [security2:error] [pid 17789:tid 17789] [client 2a03:2880:f806:13:::43046] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||roselockecasting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "roselockecasting.com"] [uri "/roselockecasting.com"] [unique_id "aS96HjXCc3omqwDqgDC5ZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2025-12-01 21:44:15
(9 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 20:44:32
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 15:44:27.190917 2025] [security2:error] [pid 6394:tid 6394] [client 2a03:2880:f806:13:::42926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudehotsauces.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudehotsauces.com"] [uri "/dudehotsauces.com"] [unique_id "aS3-K_XBbIf5it4efwPATwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-30 02:54:04
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 21:53:58.388691 2025] [security2:error] [pid 22547:tid 22547] [client 2a03:2880:f806:13:::38288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/23368"] [unique_id "aSuxxm9zoBXkc306th0KXwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
tr1n
2025-11-29 19:32:35
(9 months ago)
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
ASN: 32934 (FACEBOOK)
...
show more
Triggered Cloudflare WAF (linkMaze) from US.
Action taken: LINK_MAZE_INJECTED
ASN: 32934 (FACEBOOK)
Protocol: HTTP/2 (GET method)
Endpoint: /SiteMap.aspx
Timestamp: 2025-11-29T19:32:35Z
UA: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-28 05:47:29
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 00:47:19.851827 2025] [security2:error] [pid 24997:tid 24997] [client 2a03:2880:f806:13:::55294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adonamusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adonamusic.com"] [uri "/adonamusic.com"] [unique_id "aSk3Z12xrP4UBY_OnKHK4QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 04:41:31
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 23:41:27.260781 2025] [security2:error] [pid 25825:tid 25825] [client 2a03:2880:f806:13:::33520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "aSkn90B7wS4-dTJM5l-b1wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2025-11-25 17:46:24
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /blog/tag/motor-para-portao-de-correr-garen/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
LotPhantom
2025-11-25 01:59:44
(9 months ago)
2a03:2880:f806:13:: - - [25/Nov/2025:01:58:43 +0000] "GET /SiteMap.aspx HTTP/2.0" 404 9 "-" "meta-ex ...
show more
2a03:2880:f806:13:: - - [25/Nov/2025:01:58:43 +0000] "GET /SiteMap.aspx HTTP/2.0" 404 9 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack