๐บ๐ธ
Mehmet_The_Script_Kiddie
2026-03-15 21:31:57
(6 months ago)
CloudFlare WAF REPORT: /sitemap.xml
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-03-15 18:00:26
(6 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protoco ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protocol: HTTP/2 (GET method)
Endpoint: /sitemap-index.xml
Timestamp: 2026-03-15T16:37:46Z
User-Agent: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 17:45:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 13:45:10.101183 2026] [security2:error] [pid 6219:tid 6219] [client 2a03:2880:f806:28:::52187] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "abbwJheaGblT71DOZlejPQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
BSG Webmaster
2026-03-15 13:55:38
(6 months ago)
Hacking Attempt using path /sitemap.txt
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 13:48:37
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 09:48:32.574568 2026] [security2:error] [pid 3144:tid 3144] [client 2a03:2880:f806:28:::22053] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stickittomebuttons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stickittomebuttons.com"] [uri "/stickittomebuttons.com"] [unique_id "aba4sEfL7j0dr_M53vBifgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 13:29:45
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 09:29:39.080863 2026] [security2:error] [pid 7810:tid 7810] [client 2a03:2880:f806:28:::54207] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||3-6trucking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3-6trucking.com"] [uri "/3-6trucking.com"] [unique_id "aba0QwyNgV8TmCUFrUlFsgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-03-15 11:41:59
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /blog/ha-hugo-stack/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 10:20:18
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 06:20:12.243315 2026] [security2:error] [pid 27197:tid 27197] [client 2a03:2880:f806:28:::47179] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||book-arts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "book-arts.com"] [uri "/book-arts.com"] [unique_id "abaH3MvTduSsBM8KdFXVFgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
blinx
2026-03-15 09:33:14
(6 months ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Mehmet_The_Script_Kiddie
2026-03-15 07:03:17
(6 months ago)
CloudFlare WAF REPORT: Disobey robots.txt. Suspicious web crawler.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 01:39:06
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 21:39:00.790891 2026] [security2:error] [pid 3552788:tid 3552788] [client 2a03:2880:f806:28:::56763] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "abYNtM90KWWe0gBWe8OoRQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 00:49:59
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 20:49:54.148580 2026] [security2:error] [pid 7357:tid 7357] [client 2a03:2880:f806:28:::43467] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellart.com"] [uri "/mitchellart.com"] [unique_id "abYCMjXt32qFZwj2KiuDOgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-14 22:25:13
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-14 20:24:18
(6 months ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 16:24:13.191591 2026] [security2:error] [pid 23107:tid 23107] [client 2a03:2880:f806:28:::62863] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/nav.php"] [unique_id "abXD7Rd0hLt_A9tPaAU1NwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 04:20:07
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:28:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 00:20:02.029918 2026] [security2:error] [pid 32261:tid 32261] [client 2a03:2880:f806:28:::43157] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoretopicturenetwork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoretopicturenetwork.com"] [uri "/scoretopicturenetwork.com"] [unique_id "abDtct4tPtMewJJjZc2fxQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack