πΊπΈ
TPI-Abuse
2025-11-25 00:15:46
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:15:39.860038 2025] [security2:error] [pid 16515:tid 16515] [client 2a03:2880:f806:2d:::41746] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||danged.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danged.com"] [uri "/danged.com"] [unique_id "aST1K1LkCwMC6-mvkjUs3wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Mehmet_The_Script_Kiddie
2025-11-21 21:15:13
(9 months ago)
CloudFlare WAF REPORT: /sitemap.txt
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2025-11-20 14:44:58
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/dz-max-fit-connect-1-2/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π³π±
Roderic
2025-11-19 02:45:48
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-11-17 21:15:15
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 16:15:08.915255 2025] [security2:error] [pid 14697:tid 14697] [client 2a03:2880:f806:2d:::60560] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "aRuQXE02tPdVNklgABx9BwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-16 20:21:22
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 15:21:17.434765 2025] [security2:error] [pid 606386:tid 606386] [client 2a03:2880:f806:2d:::58900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellart.com"] [uri "/mitchellart.com"] [unique_id "aRoyPWvZYPF2Jz0z10RaqgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-16 15:23:03
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 10:22:58.476663 2025] [security2:error] [pid 32676:tid 32676] [client 2a03:2880:f806:2d:::39802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nancyscafeandcatering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/futurequestacademy.com"] [unique_id "aRnsUoEoIOJzCB4gs1o8ewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2025-11-13 00:46:33
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
π©πͺ
conseilgouz
2025-11-11 18:29:33
(9 months ago)
lae-88 : Bloc AI bots=>/sitemap_index.xml(meta-external)
Hacking
π©πͺ
Didier Lagaert
2025-11-11 18:29:11
(9 months ago)
lie-88 : Bloc AI bots=>/news_sitemap.xml(meta-external)
Hacking
πΊπΈ
TPI-Abuse
2025-11-06 02:20:24
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 21:20:17.150448 2025] [security2:error] [pid 7567:tid 7567] [client 2a03:2880:f806:2d:::40052] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matteozacchino.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matteozacchino.com"] [uri "/matteozacchino.com"] [unique_id "aQwF4YMUmf1z6bLxAxpZ0gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-06 01:53:44
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 20:53:39.882961 2025] [security2:error] [pid 18800:tid 18800] [client 2a03:2880:f806:2d:::40628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||naturessecretresort.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "naturessecretresort.com"] [uri "/naturessecretresort.com"] [unique_id "aQv_o9UZQk9bmwEN3kx8AgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-03 03:46:04
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 22:45:56.980760 2025] [security2:error] [pid 9111:tid 9111] [client 2a03:2880:f806:2d:::35876] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intrinsicdiscovery.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intrinsicdiscovery.com"] [uri "/intrinsicdiscovery.com"] [unique_id "aQgldFq9FDl9nPjU4fPgaQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-01 19:17:27
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 15:17:23.146652 2025] [security2:error] [pid 31759:tid 31759] [client 2a03:2880:f806:2d:::60950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vangentholding.com|F|2"] [data ".yolasite.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vangentholding.com"] [uri "/uncategorized/asian-market-down-amid-korean-tensions-3/cohoiduhoc.yolasite.com"] [unique_id "aQZcw-BCJqnnVnllrI2kuQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-31 16:49:40
(10 months ago)
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:2d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 31 12:49:34.230997 2025] [security2:error] [pid 19130:tid 19130] [client 2a03:2880:f806:2d:::59576] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)((?:\\\\bx(?:link:href|html|mlns)|!ENTITY\\\\b.{0,399}?\\\\b(?:SYSTEM|PUBLIC)|\\\\bdata:text\\\\/html))" at ARGS:_bd_prev_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "170"] [id "213060"] [rev "7"] [msg "COMODO WAF: XSS Filter - Category 3: Attribute Vector||essentialee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "essentialee.com"] [uri "/"] [unique_id "aQToni98P6SnWZFxaOC5dwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack