πΊπΈ
TPI-Abuse
2025-11-29 20:10:52
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 15:10:48.081879 2025] [security2:error] [pid 6695:tid 6695] [client 2a03:2880:f806:33:::53774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "aStTSOhdedKlJtsPsv-izAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-28 20:03:57
(9 months ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 15:03:47.379046 2025] [security2:error] [pid 27675:tid 27675] [client 2a03:2880:f806:33:::55060] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||beckersystems.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "beckersystems.net"] [uri "/beckerwiki/index.php"] [unique_id "aSoAI8YRv8Kr67e5kulZTQAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2025-11-26 01:40:28
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-11-25 00:12:22
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 19:12:15.145597 2025] [security2:error] [pid 29197:tid 29197] [client 2a03:2880:f806:33:::60642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vc1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vc1.com"] [uri "/vc1.com"] [unique_id "aST0Xw7yLq7jTKtonnJ6wwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-20 12:18:41
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 07:18:37.001569 2025] [security2:error] [pid 2193978:tid 2193995] [client 2a03:2880:f806:33:::47310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||businessbasicsinstitute.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "businessbasicsinstitute.com"] [uri "/businessbasicsinstitute.com"] [unique_id "aR8HHBlLBDE0I86MwVXwywAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2025-11-19 02:45:47
(10 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-11-18 05:30:08
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 00:30:01.646991 2025] [security2:error] [pid 21944:tid 21944] [client 2a03:2880:f806:33:::58332] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hakkawok.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hakkawok.com"] [uri "/hakkawok.com"] [unique_id "aRwEWUCUyR6LVVXphd9oWgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-17 19:01:17
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 14:01:13.486087 2025] [security2:error] [pid 26281:tid 26281] [client 2a03:2880:f806:33:::50468] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/99105"] [unique_id "aRtw-cqyoF76nCnHMWR6OQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-17 13:13:47
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 08:13:44.291508 2025] [security2:error] [pid 5411:tid 5411] [client 2a03:2880:f806:33:::46020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sargous.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sargous.com"] [uri "/sargous.com"] [unique_id "aRsfiBGJKO9O7y6SSHNLuAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-17 08:20:56
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 03:20:51.497186 2025] [security2:error] [pid 28765:tid 28765] [client 2a03:2880:f806:33:::37256] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robslasercreations.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robslasercreations.com"] [uri "/robslasercreations.com"] [unique_id "aRra4xk8ZIGr_RSSf7SzPQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2025-11-12 17:47:10
(10 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
π©πͺ
conseilgouz
2025-11-11 18:33:44
(10 months ago)
ave-88 : Bloc AI bots=>/news_sitemap.xml(meta-external)
Hacking
π©πͺ
conseilgouz
2025-11-11 18:16:37
(10 months ago)
doe-88 : Bloc AI bots=>/sitemap.xml(meta-external)
Hacking
π«π·
mrcrassi
2025-11-11 08:59:13
(10 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/bv-fit-ramp/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
ipblock.com
2025-11-11 08:30:00
(10 months ago)
IPBlock protected site ID [4055-d][s=03].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack