๐บ๐ธ
TPI-Abuse
2026-03-15 02:27:51
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 22:27:46.083982 2026] [security2:error] [pid 32523:tid 32523] [client 2a03:2880:f806:22:::46629] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||protexiasecure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "protexiasecure.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "abYZIjb08Tc7krLPLbTIAgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-15 00:51:29
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-14 20:09:28
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 16:09:22.816008 2026] [security2:error] [pid 20392:tid 20392] [client 2a03:2880:f806:22:::63739] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockwaychiropractic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockwaychiropractic.com"] [uri "/rockwaychiropractic.com"] [unique_id "abXAclA2PpFzjachvWUu-QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 22:37:40
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 18:37:35.969480 2026] [security2:error] [pid 2737:tid 2737] [client 2a03:2880:f806:22:::62959] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kiinlog.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kiinlog.com"] [uri "/kiinlog.com"] [unique_id "abNAL2o6RF4P4NH95KVlFQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-12 13:23:52
(6 months ago)
Automated honeypot detection on bbd.fan: probed /admin | UA: meta-webindexer/1.1 (+https://developer ...
show more
Automated honeypot detection on bbd.fan: probed /admin | UA: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-10 23:05:32
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 19:05:26.161830 2026] [security2:error] [pid 570:tid 570] [client 2a03:2880:f806:22:::24297] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||raynernet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raynernet.com"] [uri "/raynernet.com"] [unique_id "abCjtrFP5oaPq8Jk0B8zxQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-09 18:25:24
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 14:25:19.240569 2026] [security2:error] [pid 8542:tid 8542] [client 2a03:2880:f806:22:::53723] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||credenda.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "credenda.com"] [uri "/credenda.com"] [unique_id "aa8Qj1Ai0ysVcMux0ZbUwgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-08 22:58:55
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐ซ๐ท
mrcrassi
2026-03-08 20:37:00
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/dz-niid/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-07 20:58:05
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 07 15:57:57.319714 2026] [security2:error] [pid 26610:tid 26610] [client 2a03:2880:f806:22:::42533] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||major33.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "major33.com"] [uri "/major33.com"] [unique_id "aayRVY__UeQ4JiXqkot7CAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-06 01:46:51
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 05 20:46:48.071188 2026] [security2:error] [pid 4181:tid 4181] [client 2a03:2880:f806:22:::54869] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wallawallafirearmstraining.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wallawallafirearmstraining.com"] [uri "/wallawallafirearmstraining.com"] [unique_id "aaoyCL-CHX6eG7qtMhB5hwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 02:59:53
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 21:59:48.791406 2026] [security2:error] [pid 14873:tid 14873] [client 2a03:2880:f806:22:::44957] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||owenmail.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "owenmail.com"] [uri "/owenmail.com"] [unique_id "aaT9JMOWemvalbQQipMTSAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 01:17:41
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 20:17:33.792588 2026] [security2:error] [pid 5501:tid 5501] [client 2a03:2880:f806:22:::52167] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cpking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cpking.com"] [uri "/cpking.com"] [unique_id "aZ-fLXXSds7praX79EfL3AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 03:00:57
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 22:00:50.692308 2026] [security2:error] [pid 25321:tid 25321] [client 2a03:2880:f806:22:::47675] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||computerservicesofflorida.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "computerservicesofflorida.com"] [uri "/computerservicesofflorida.com"] [unique_id "aZvC4o8hLsBIp8Vw-vCNHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 05:42:23
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:22:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 00:42:19.792499 2026] [security2:error] [pid 16914:tid 16914] [client 2a03:2880:f806:22:::34931] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nancyscafeandcatering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/dailymaturelove.com"] [unique_id "aZaiu_7gG3-VeNOg8jzpIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack