πΊπΈ
TPI-Abuse
2026-03-15 01:47:43
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 21:47:36.197523 2026] [security2:error] [pid 24473:tid 24473] [client 2a03:2880:f806:32:::21309] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertautoworks.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "abYPuIgc0HQXq1QOcGQxVAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-15 00:20:48
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 20:20:41.312623 2026] [security2:error] [pid 26607:tid 26612] [client 2a03:2880:f806:32:::25341] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gelatoconsapevole.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gelatoconsapevole.com"] [uri "/gelatoconsapevole.com"] [unique_id "abX7Wbxnjk-KRBF6lbZkswAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-14 21:37:15
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
πΊπΈ
TPI-Abuse
2026-03-13 18:20:29
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 14:20:21.822547 2026] [security2:error] [pid 1746707:tid 1746707] [client 2a03:2880:f806:32:::28231] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "abRVZe2b4eY-3jgtJuOXugAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-11 17:02:14
(5 months ago)
Blocking for trying to access an exploit file: /myagent.site
Hacking
πΊπΈ
TPI-Abuse
2026-03-09 21:19:50
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 17:19:43.113496 2026] [security2:error] [pid 32170:tid 32170] [client 2a03:2880:f806:32:::55315] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stickittomebuttons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stickittomebuttons.com"] [uri "/stickittomebuttons.com"] [unique_id "aa85b9AjISfHe7Wh9FS71wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2026-03-09 00:56:01
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/trava-eletrica-para-portoes-automaticos/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-03-08 22:31:27
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 18:31:23.602436 2026] [security2:error] [pid 19858:tid 19858] [client 2a03:2880:f806:32:::43271] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||baselinesc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "baselinesc.com"] [uri "/baselinesc.com"] [unique_id "aa34u3200jWVDdJPD0jDXwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-07 21:49:13
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 07 16:49:08.979856 2026] [security2:error] [pid 5552:tid 5552] [client 2a03:2880:f806:32:::52837] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||star-discgolf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "star-discgolf.com"] [uri "/star-discgolf.com"] [unique_id "aaydVJ_NNU_DI6lwn83Y5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
myagent.site
2026-03-06 00:37:16
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
πΊπΈ
TPI-Abuse
2026-03-02 03:22:51
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 22:22:44.855765 2026] [security2:error] [pid 19608:tid 19608] [client 2a03:2880:f806:32:::57405] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||darkalleyproductions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "darkalleyproductions.com"] [uri "/darkalleyproductions.com"] [unique_id "aaUChDPZRd1_9SYzbYFxEwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-01 04:24:35
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 23:24:28.764795 2026] [security2:error] [pid 15017:tid 15017] [client 2a03:2880:f806:32:::56255] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kclawoffice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kclawoffice.com"] [uri "/kclawoffice.com"] [unique_id "aaO_fAvO95pCdXXUTB01nwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-28 23:48:13
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 18:48:05.487299 2026] [security2:error] [pid 32057:tid 32057] [client 2a03:2880:f806:32:::60785] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jamroomrecording.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jamroomrecording.com"] [uri "/jamroomrecording.com"] [unique_id "aaN-tT6hF2I8C58PFOOxHgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-24 03:26:19
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 22:26:15.701832 2026] [security2:error] [pid 26348:tid 26348] [client 2a03:2880:f806:32:::51375] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||impostersyndromeunmasked.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "impostersyndromeunmasked.com"] [uri "/impostersyndromeunmasked.com"] [unique_id "aZ0aVyKVkGrEdCPXFycjXQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-24 03:10:07
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 22:10:00.784339 2026] [security2:error] [pid 1749:tid 1749] [client 2a03:2880:f806:32:::22383] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellart.com"] [uri "/mitchellart.com"] [unique_id "aZ0WiKRS4gKNI9M7O4L-YQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack