๐บ๐ธ
TPI-Abuse
2025-11-21 23:43:50
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 18:43:30.238948 2025] [security2:error] [pid 17306:tid 17306] [client 2a03:2880:f806:17:::51968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||naturessecretresort.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "naturessecretresort.com"] [uri "/naturessecretresort.com"] [unique_id "aSD5Im77g8907BgCajxyuAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2025-11-20 01:47:43
(10 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produtos/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-19 09:30:42
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 04:30:39.716100 2025] [security2:error] [pid 26189:tid 26189] [client 2a03:2880:f806:17:::54564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||noscentpro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "noscentpro.com"] [uri "/noscentpro.com"] [unique_id "aR2OP9ozRXCPPYP029Vh4QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-17 14:04:20
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 09:04:15.926267 2025] [security2:error] [pid 1719998:tid 1720015] [client 2a03:2880:f806:17:::40490] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||businessbasicsinstitute.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "businessbasicsinstitute.com"] [uri "/businessbasicsinstitute.com"] [unique_id "aRsrX2y48Qh08jDPJG-cSwAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-14 00:53:53
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 19:53:47.020523 2025] [security2:error] [pid 1160190:tid 1160190] [client 2a03:2880:f806:17:::60528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellart.com"] [uri "/mitchellart.com"] [unique_id "aRZ9mz786uADUuAijYvCtgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 21:30:45
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 16:30:37.438512 2025] [security2:error] [pid 3540:tid 3540] [client 2a03:2880:f806:17:::44096] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matteozacchino.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matteozacchino.com"] [uri "/matteozacchino.com"] [unique_id "aRZN_XzJKDoVyDpGpDV6nQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2025-11-11 18:33:36
(10 months ago)
ave-88 : Bloc AI bots=>/sitemap_index.xml(meta-external)
Hacking
๐ฉ๐ช
conseilgouz
2025-11-08 06:26:59
(11 months ago)
doe-88 : Bloc AI bots=>/sitemap_index.xml(meta-external)
Hacking
๐บ๐ธ
TPI-Abuse
2025-10-26 20:38:33
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 26 16:38:28.000684 2025] [security2:error] [pid 23345:tid 23345] [client 2a03:2880:f806:17:::53262] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.fractalsky.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.fractalsky.com"] [uri "/blackhorrormovie.com"] [unique_id "aP6Gw_XsT0G_HnGKwKS9SQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-18 21:58:20
(11 months ago)
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 18 17:58:15.460152 2025] [security2:error] [pid 4232:tid 4232] [client 2a03:2880:f806:17:::57942] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)((?:\\\\bx(?:link:href|html|mlns)|!ENTITY\\\\b.{0,399}?\\\\b(?:SYSTEM|PUBLIC)|\\\\bdata:text\\\\/html))" at ARGS:_bd_prev_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "170"] [id "213060"] [rev "7"] [msg "COMODO WAF: XSS Filter - Category 3: Attribute Vector||essentialee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "essentialee.com"] [uri "/"] [unique_id "aPQNdxNRfcarGUKtQpViKQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-29 18:57:12
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 14:57:07.403237 2025] [security2:error] [pid 18476:tid 18476] [client 2a03:2880:f806:17:::46994] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/217507"] [unique_id "aNrWgz76d60jXITbkTHf-wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-28 04:03:10
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:17:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 28 00:03:05.995298 2025] [security2:error] [pid 30849:tid 30849] [client 2a03:2880:f806:17:::41464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lertap5.com|F|2"] [data ".xlsx - shortcut.lnk"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lertap5.com"] [uri "/Documentation/Samples/Iteman5/Geo431/Geology431_DIFwork_2016.xlsx - Shortcut.lnk"] [unique_id "aNizeUkp1I3Z73V5756ALwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
COMPLEX
2025-09-24 07:24:16
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 32934 (FACEB ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 32934 (FACEBOOK)
Protocol: HTTP/2 (GET method)
Endpoint: /index.html
show less
Bad Web Bot
๐จ๐ญ
blinx
2025-08-23 21:21:21
(1 year ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2025-08-18 17:32:28
(1 year ago)
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. (1100000-173)
show less
Bad Web Bot