๐ญ๐บ
kranem
2026-03-16 00:02:08
(5 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protoco ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protocol: HTTP/2 (GET method)
Endpoint: /sitemap_index.xml
Timestamp: 2026-03-15T22:41:40Z
User-Agent: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 23:18:32
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 19:18:26.165122 2026] [security2:error] [pid 2977:tid 2977] [client 2a03:2880:f806:34:::43239] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cw-enterprises.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cw-enterprises.com"] [uri "/cw-enterprises.com"] [unique_id "abc-QrOh8WtXqeIZboQJkgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-15 20:53:24
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐ฌ๐ง
pinguin
2026-03-15 17:49:47
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /blog/ha-hugo-stack/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
BSG Webmaster
2026-03-15 14:19:40
(5 months ago)
Hacking Attempt using path /sitemap.txt
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 14:00:11
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 10:00:06.547042 2026] [security2:error] [pid 21084:tid 21091] [client 2a03:2880:f806:34:::20837] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||missalastages.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "missalastages.com"] [uri "/missalastages.com"] [unique_id "aba7ZltXLTJbnsDx3fXr0AAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 12:45:27
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 08:45:24.418774 2026] [security2:error] [pid 5099:tid 5099] [client 2a03:2880:f806:34:::26979] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||amazingwelding.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazingwelding.com"] [uri "/amazingwelding.com"] [unique_id "abap5B_GsGu6WwBF6N3dSgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 10:08:32
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 06:08:26.123864 2026] [security2:error] [pid 23147:tid 23147] [client 2a03:2880:f806:34:::55715] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grancanariaholidays.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grancanariaholidays.com"] [uri "/grancanariaholidays.com"] [unique_id "abaFGh-K3dAweUZeXW2fKAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 09:21:49
(5 months ago)
(mod_security) mod_security (id:211540) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:211540) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 05:21:42.548903 2026] [security2:error] [pid 19782:tid 19782] [client 2a03:2880:f806:34:::33883] ModSecurity: Access denied with code 403 (phase 2). Match of "contains /wp-json/yoast/" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "17"] [id "211540"] [rev "14"] [msg "COMODO WAF: Blind SQL Injection Attack||mail.computerian.net|F|2"] [data "Matched Data: substring found within REQUEST_URI: /detail.php?shop/substring/transmigrator98606268649.html"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "mail.computerian.net"] [uri "/detail.php"] [unique_id "abZ6Jm7o4nEY2Gw0cgPuCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 07:49:54
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 03:49:49.491926 2026] [security2:error] [pid 14504:tid 14504] [client 2a03:2880:f806:34:::65105] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automationmp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automationmp.com"] [uri "/automationmp.com"] [unique_id "abZknd300EdSeAC3dQHgpwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 07:22:45
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 03:22:38.574467 2026] [security2:error] [pid 3845659:tid 3845659] [client 2a03:2880:f806:34:::36571] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "abZePo6jMTJMXbMHhwps6gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 03:59:29
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 23:59:26.229212 2026] [security2:error] [pid 29086:tid 29086] [client 2a03:2880:f806:34:::22639] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockwaychiropractic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockwaychiropractic.com"] [uri "/rockwaychiropractic.com"] [unique_id "abYuntMgGVK9byDS6mowqgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 22:16:49
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:34:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 18:16:45.503854 2026] [security2:error] [pid 6633:tid 6633] [client 2a03:2880:f806:34:::23333] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arellasoc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arellasoc.com"] [uri "/arellasoc.com"] [unique_id "abXeTTyDsNaBGK66D-YvywAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-14 18:30:16
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
myagent.site
2026-03-10 22:21:00
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking