πΊπΈ
TPI-Abuse
2026-03-15 08:59:52
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 04:59:49.398964 2026] [security2:error] [pid 24518:tid 24518] [client 2a03:2880:f806:26:::41081] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.iee-usa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.iee-usa.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "abZ1Bchi3-K_SKnerh_BYgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-15 07:14:51
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 03:14:47.579707 2026] [security2:error] [pid 20269:tid 20269] [client 2a03:2880:f806:26:::24205] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||book-arts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "book-arts.com"] [uri "/book-arts.com"] [unique_id "abZcZ_v5KMuVzLMvHQqjlAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨πΏ
antihack.anarchista.xyz
2026-03-14 23:54:52
(6 months ago)
404 burst: 20 hits in 5 min, URI /ministerstvo-obrany-zahajilo-jednani-o-porizeni-transportnich-leto ...
show more
404 burst: 20 hits in 5 min, URI /ministerstvo-obrany-zahajilo-jednani-o-porizeni-transportnich-letounu-c-390-millennium/, Ref , UA meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Brute-Force
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-03-14 23:48:02
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 19:47:53.338159 2026] [security2:error] [pid 11763:tid 11763] [client 2a03:2880:f806:26:::31789] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automationmp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automationmp.com"] [uri "/automationmp.com"] [unique_id "abXzqUYJ5w8EPKrgxqQLHQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-14 22:43:42
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
πΊπΈ
TPI-Abuse
2026-03-14 22:37:51
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 18:37:46.383361 2026] [security2:error] [pid 7731:tid 7731] [client 2a03:2880:f806:26:::28507] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||raynernet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raynernet.com"] [uri "/raynernet.com"] [unique_id "abXjOqbsNSrwz3KciMPjMwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 18:20:54
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 14:20:49.281774 2026] [security2:error] [pid 11039:tid 11083] [client 2a03:2880:f806:26:::45077] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||businessbasicsinstitute.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "businessbasicsinstitute.com"] [uri "/businessbasicsinstitute.com"] [unique_id "abWnASmXJb0uQoGSlhdwgAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-13 21:57:53
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
πΊπΈ
TPI-Abuse
2026-03-13 19:18:10
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 15:18:05.350916 2026] [security2:error] [pid 12230:tid 12230] [client 2a03:2880:f806:26:::63017] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||natchezbicycle.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "natchezbicycle.com"] [uri "/natchezbicycle.com"] [unique_id "abRi7YH1kICmFNSydDy0BQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-11 03:58:11
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
π«π·
mrcrassi
2026-03-11 02:20:51
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/grand-pivo/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
myagent.site
2026-03-08 01:36:20
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
πΊπΈ
TPI-Abuse
2026-03-03 02:30:09
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 21:30:02.540974 2026] [security2:error] [pid 20590:tid 20590] [client 2a03:2880:f806:26:::48695] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||go-901.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "go-901.com"] [uri "/go-901.com"] [unique_id "aaZHqsmvpq25wBE4uVVVugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-03 00:04:33
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 19:04:29.424392 2026] [security2:error] [pid 3288:tid 3288] [client 2a03:2880:f806:26:::46341] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intrinsicdiscovery.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intrinsicdiscovery.com"] [uri "/intrinsicdiscovery.com"] [unique_id "aaYljUD7fvc4ZOdJIMkp3wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-27 05:12:25
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:26:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 00:12:18.197109 2026] [security2:error] [pid 22597:tid 22597] [client 2a03:2880:f806:26:::54881] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shinynew.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shinynew.com"] [uri "/shinynew.com"] [unique_id "aaEnsvaYyzBgGNgi0Lu39AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack