๐บ๐ธ
TPI-Abuse
2026-02-20 09:34:08
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 04:34:02.923206 2026] [security2:error] [pid 13289:tid 13289] [client 2a03:2880:f806:32:::63499] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nesetsv.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nesetsv.com"] [uri "/nesetsv.com"] [unique_id "aZgqiqIStXNtUpQWft3kRAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 22:05:08
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 17:05:04.028029 2026] [security2:error] [pid 11882:tid 11882] [client 2a03:2880:f806:32:::57383] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||microscopedia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "microscopedia.com"] [uri "/microscopedia.com"] [unique_id "aZY3kAGEtMjtd8CWmB7YmQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-17 21:41:55
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 17 16:41:49.435144 2026] [security2:error] [pid 20014:tid 20014] [client 2a03:2880:f806:32:::49629] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||owenmail.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "owenmail.com"] [uri "/owenmail.com"] [unique_id "aZTgnTwKNTIM0jKOqsw-aQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-12-03 22:58:30
(8 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
Anonymous
2025-12-03 12:48:41
(8 months ago)
[Wed Dec 03 13:41:37.688502 2025] [authz_core:error] [pid 2471345:tid 2748106] [remote 2a03:2880:f80 ...
show more
[Wed Dec 03 13:41:37.688502 2025] [authz_core:error] [pid 2471345:tid 2748106] [remote 2a03:2880:f806:32:::54350] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:45:48.151637 2025] [authz_core:error] [pid 2471489:tid 2471503] [remote 2a03:2880:f806:32:::46604] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:48:40.853646 2025] [authz_core:error] [pid 2471345:tid 2748100] [remote 2a03:2880:f806:32:::38982] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-02 23:43:21
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 18:43:14.761348 2025] [security2:error] [pid 27045:tid 27045] [client 2a03:2880:f806:32:::57630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sargous.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sargous.com"] [uri "/sargous.com"] [unique_id "aS95kltcX-EdQlve-tMS1gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
crypto i trust, hold i must
2025-12-01 21:39:48
(8 months ago)
Automated vulnerability scanner detected. User-Agent: meta-externalagent/1.1 (+https://developers.fa ...
show more
Automated vulnerability scanner detected. User-Agent: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
crypto i trust, hold i must
2025-11-29 20:23:38
(8 months ago)
Automated vulnerability scanner detected. User-Agent: meta-externalagent/1.1 (+https://developers.fa ...
show more
Automated vulnerability scanner detected. User-Agent: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-29 19:51:10
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 14:51:05.027579 2025] [security2:error] [pid 10592:tid 10592] [client 2a03:2880:f806:32:::53520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leirstein.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leirstein.com"] [uri "/leirstein.com"] [unique_id "aStOqc0cjKz4LqXRzNDtjAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-11-29 19:31:28
(8 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-28 06:15:35
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 01:15:28.144170 2025] [security2:error] [pid 10006:tid 10006] [client 2a03:2880:f806:32:::43718] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mariarozella.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mariarozella.com"] [uri "/mariarozella.com"] [unique_id "aSk-AMJc0YZPTwXqAGdqlAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-27 05:47:43
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 00:47:39.272179 2025] [security2:error] [pid 11374:tid 11374] [client 2a03:2880:f806:32:::60136] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jamroomrecording.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jamroomrecording.com"] [uri "/jamroomrecording.com"] [unique_id "aSfl-4Z2ssH99JDGRnaTtgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2025-11-25 18:23:53
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-22 19:18:19
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 22 14:18:13.360121 2025] [security2:error] [pid 7181:tid 7181] [client 2a03:2880:f806:32:::40834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "aSIMdQfQCsCQKeh0KM9O5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 18:45:14
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:32:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 13:45:07.859712 2025] [security2:error] [pid 21306:tid 21306] [client 2a03:2880:f806:32:::48104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grancanariaholidays.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grancanariaholidays.com"] [uri "/grancanariaholidays.com"] [unique_id "aSCzM7mNHx-qaIIQvD1qfQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack