๐บ๐ธ
TPI-Abuse
2026-03-15 02:24:09
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 22:24:01.182089 2026] [security2:error] [pid 13618:tid 13623] [client 2a03:2880:f806:35:::39217] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.charteredwealthmanager.aafm.us|F|2"] [data ".gafm.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.charteredwealthmanager.aafm.us"] [uri "/www.GAFM.com"] [unique_id "abYYQSCVA22sZgglMZ1QRQAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-14 21:59:12
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐ธ๐ฌ
mypatricks
2026-03-12 10:22:20
(6 months ago)
2a03:2880:f806:35::/249.42.188.64 | Port: 12091 | DNS: 2a03:2880:f806:35:: 2026-03-12T18:22:19+08:00 ...
show more
2a03:2880:f806:35::/249.42.188.64 | Port: 12091 | DNS: 2a03:2880:f806:35:: 2026-03-12T18:22:19+08:00 America/New_York | Un-authorized bots or crawlers | UA: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler) HTTP/1.1 443 GET | URL: / | Ref: - | Country: US/United States/-08:00 IP City: Atlanta 9db213b8dd36b088-ATL/Atlanta, GA, United States 1 hits/0 secs Robots 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐บ๐ธ
myagent.site
2026-03-11 03:55:07
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
myagent.site
2026-03-09 00:41:05
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐ซ๐ท
mrcrassi
2026-03-08 20:31:15
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/terminal-facial-garen-5001/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
myagent.site
2026-03-05 23:58:46
(7 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-04 22:16:59
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 17:16:54.941890 2026] [security2:error] [pid 18126:tid 18126] [client 2a03:2880:f806:35:::32265] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cw-enterprises.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cw-enterprises.com"] [uri "/cw-enterprises.com"] [unique_id "aaivVtKqzyadjE_are19UAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 23:42:32
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 18:42:27.588812 2026] [security2:error] [pid 27660:tid 27660] [client 2a03:2880:f806:35:::47197] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.player-care.us|F|2"] [data ".spencerserolls.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.player-care.us"] [uri "/cb/www.spencerserolls.com"] [unique_id "aaYgYxnmJKJbDx2QJANL3gAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-02 00:00:48
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 19:00:43.790111 2026] [security2:error] [pid 30981:tid 30981] [client 2a03:2880:f806:35:::35537] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "aaTTK7LBgyEmKAcfcP-pSwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 04:51:48
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 23:51:41.563965 2026] [security2:error] [pid 24277:tid 24277] [client 2a03:2880:f806:35:::38233] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "aaPF3WoGUlvewWmCFTWZ3QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-01 01:37:02
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 20:36:58.571555 2026] [security2:error] [pid 972:tid 972] [client 2a03:2880:f806:35:::58621] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||raynernet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raynernet.com"] [uri "/raynernet.com"] [unique_id "aaOYOjrRrCN1K3UqGFCFEwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 05:46:40
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 00:46:32.063720 2026] [security2:error] [pid 31743:tid 31743] [client 2a03:2880:f806:35:::28597] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||caddydad.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caddydad.com"] [uri "/caddydad.com"] [unique_id "aaKBOMtlsxrBp2K7Y659FAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-27 03:22:56
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 22:22:53.376712 2026] [security2:error] [pid 15714:tid 15714] [client 2a03:2880:f806:35:::54311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||go-901.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "go-901.com"] [uri "/go-901.com"] [unique_id "aaEODeM50PxrJ8Je7G-hdwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 01:08:36
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:35:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 20:08:28.193679 2026] [security2:error] [pid 20375:tid 20375] [client 2a03:2880:f806:35:::33243] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellart.com"] [uri "/mitchellart.com"] [unique_id "aZ-dDAdrO7fdFI2CHLv0jQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack