๐บ๐ธ
myagent.site
2026-03-15 01:32:05
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
BSG Webmaster
2026-03-15 01:25:03
(6 months ago)
Hacking Attempt using path /sitemap.txt
Brute-Force
Web App Attack
๐จ๐ฟ
antihack.anarchista.xyz
2026-03-15 00:50:18
(6 months ago)
404 burst: 30 hits in 10 min, URI /policia-prosi-o-pomoc-patraju-po-samuelovi-z-oravy-chcel-cestovat ...
show more
404 burst: 30 hits in 10 min, URI /policia-prosi-o-pomoc-patraju-po-samuelovi-z-oravy-chcel-cestovat-po-svete-no-naposledy-sa-ozval-z-letiska-v-istanbule/, Ref , UA meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Brute-Force
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 00:29:28
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 20:29:20.857021 2026] [security2:error] [pid 11735:tid 11735] [client 2a03:2880:f806:1c:::44765] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "abX9YBIpt3nFL0JKgddFJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 21:50:19
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 17:50:12.624280 2026] [security2:error] [pid 15837:tid 15837] [client 2a03:2880:f806:1c:::56737] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||3-6trucking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3-6trucking.com"] [uri "/3-6trucking.com"] [unique_id "abXYFIrrAvlSNvhR1uhawwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 16:27:23
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 12:27:14.767491 2026] [security2:error] [pid 31796:tid 31819] [client 2a03:2880:f806:1c:::62657] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||businessbasicsinstitute.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "businessbasicsinstitute.com"] [uri "/businessbasicsinstitute.com"] [unique_id "abWMYs2tkatucEKzIG1ivQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 15:34:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 11:34:10.745025 2026] [security2:error] [pid 15254:tid 15254] [client 2a03:2880:f806:1c:::20963] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "abV_8guY5iRlUEA8TIf-YAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 18:58:23
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 14:58:15.511053 2026] [security2:error] [pid 16296:tid 16296] [client 2a03:2880:f806:1c:::53639] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.drjasonkolber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.drjasonkolber.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "abMMx14t8M9P6n3uTmbJ7wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-11 02:16:37
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-11 01:23:57
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 21:23:51.124445 2026] [security2:error] [pid 16314:tid 16314] [client 2a03:2880:f806:1c:::59285] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||earlyfordv8crrg10.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "earlyfordv8crrg10.com"] [uri "/earlyfordv8crrg10.com"] [unique_id "abDEJ2-7t3OyGZkzPu7p1gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-10 23:32:50
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 19:32:46.281255 2026] [security2:error] [pid 25944:tid 25944] [client 2a03:2880:f806:1c:::56917] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||impostersyndromeunmasked.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "impostersyndromeunmasked.com"] [uri "/impostersyndromeunmasked.com"] [unique_id "abCqHsusbc3OniTwU7DEaAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 19:42:48
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 15:42:44.783525 2026] [security2:error] [pid 18203:tid 18212] [client 2a03:2880:f806:1c:::40387] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||giorgiogranozio.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "giorgiogranozio.com"] [uri "/giorgiogranozio.com"] [unique_id "aa8itKKiTzQZJ5trHxyEiAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-09 18:09:22
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-08 23:08:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 19:08:12.534956 2026] [security2:error] [pid 3653:tid 3653] [client 2a03:2880:f806:1c:::62903] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||roselockecasting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "roselockecasting.com"] [uri "/roselockecasting.com"] [unique_id "aa4BXG1IYtILivGIwRfgpQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-03-08 20:21:34
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/kdz-speed-wi-fi-1-4/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot