Anonymous
2026-04-24 01:34:34
(3 months ago)
(resource-exhaustion) Server-wide Bot Block Heavy URL: filter_ 2a03:2880:f806:37:: (US/United States ...
show more
(resource-exhaustion) Server-wide Bot Block Heavy URL: filter_ 2a03:2880:f806:37:: (US/United States/-)
show less
Hacking
π΅π±
sefinek.net
2026-04-24 00:53:46
(3 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /booru/artist/%E3%81%9F%E3%82%93%E3%81%9F%E3%82%93%E3%82%81%E3%82%93 | UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler) β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
gui-ying233
2026-04-24 00:23:04
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-23 12:09:44
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 08:09:38.131380 2026] [security2:error] [pid 3917547:tid 3917547] [client 2a03:2880:f806:37:::56570] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arellasoc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arellasoc.com"] [uri "/arellasoc.com"] [unique_id "aeoMAknpbYhShgp77p-rGAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-23 05:26:33
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 01:26:27.037873 2026] [security2:error] [pid 1985785:tid 1985860] [client 2a03:2880:f806:37:::46636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stone-doyle.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stone-doyle.com"] [uri "/stone-doyle.com"] [unique_id "aemtg0w53DQNSE2AWMEBNQAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-22 23:46:28
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 19:46:24.570127 2026] [security2:error] [pid 2911486:tid 2911486] [client 2a03:2880:f806:37:::27720] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "aeld0DTyqLtHGCW_orAb4wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-22 06:37:47
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 02:37:43.204708 2026] [security2:error] [pid 21980:tid 21980] [client 2a03:2880:f806:37:::55214] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.player-care.us|F|2"] [data ".spencerserolls.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.player-care.us"] [uri "/cb/www.spencerserolls.com"] [unique_id "aehst4gNXBeexCTczHSBjgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
london2038.com
2026-04-21 20:01:23
(4 months ago)
Too many failed requests
2a03:2880:f806:37:: - - [21/Apr/2026:19:29:04 +0200] "GET /User:DesireeWilb ...
show more
Too many failed requests
2a03:2880:f806:37:: - - [21/Apr/2026:19:29:04 +0200] "GET /User:DesireeWilber6 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [21/Apr/2026:19:48:14 +0200] "GET /User:DexterMattson4 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [21/Apr/2026:19:56:20 +0200] "GET /User:DenaLevering HTTP/2.0" 404 10156 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [21/Apr/2026:20:09:54 +0200] "GET /User:DerickGuertin63 HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [21/Apr/2026:20:36:29 +0200] "GET /User:EMNLindsay HTTP/2.0" 404 10120 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [
...
show less
Web Spam
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-19 12:15:16
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 08:15:12.764311 2026] [security2:error] [pid 2844548:tid 2844548] [client 2a03:2880:f806:37:::35580] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||laura-stone.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "laura-stone.com"] [uri "/laura-stone.com"] [unique_id "aeTHUPU1jAoxVFvRIYgmoAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-19 03:07:02
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 23:06:55.639282 2026] [security2:error] [pid 1334462:tid 1334462] [client 2a03:2880:f806:37:::44146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||haroturkiye.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "haroturkiye.com"] [uri "/haroturkiye.com"] [unique_id "aeRGz5vBIkT4nY11VNj9FgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-18 19:33:40
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 15:33:31.704273 2026] [security2:error] [pid 1293962:tid 1293962] [client 2a03:2880:f806:37:::58120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mininoarg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mininoarg.com"] [uri "/mininoarg.com"] [unique_id "aePciygwN3yka_koyO_DFAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-18 10:29:18
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 06:29:12.065041 2026] [security2:error] [pid 1864904:tid 1864904] [client 2a03:2880:f806:37:::20796] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vc1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vc1.com"] [uri "/vc1.com"] [unique_id "aeNc-EYSOW_hVlvaX-JKxgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
london2038.com
2026-04-17 23:03:42
(4 months ago)
Too many failed requests
2a03:2880:f806:37:: - - [17/Apr/2026:20:38:17 +0200] "GET /User:CurtCarneal ...
show more
Too many failed requests
2a03:2880:f806:37:: - - [17/Apr/2026:20:38:17 +0200] "GET /User:CurtCarneal HTTP/2.0" 404 10138 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:20:39:56 +0200] "GET /User:DIRRaul42567896 HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:20:40:03 +0200] "GET /User:CrystalSpruson HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:20:47:05 +0200] "GET /User:CorrineGerald HTTP/2.0" 404 10174 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:20:55:01 +0200] "GET /User:CurtEdelson41 HTTP/2.0" 404 10174 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - -
...
show less
Web Spam
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-17 05:32:32
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:37:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 01:32:28.607322 2026] [security2:error] [pid 4115962:tid 4115962] [client 2a03:2880:f806:37:::30364] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automationmp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automationmp.com"] [uri "/automationmp.com"] [unique_id "aeHF7J3oLIdFYGVhXRizEAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
london2038.com
2026-04-17 01:54:29
(4 months ago)
Too many failed requests
2a03:2880:f806:37:: - - [17/Apr/2026:00:56:05 +0200] "GET /User:NadiaHass27 ...
show more
Too many failed requests
2a03:2880:f806:37:: - - [17/Apr/2026:00:56:05 +0200] "GET /User:NadiaHass27671 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:01:08:07 +0200] "GET /User:NOQNoel649912 HTTP/2.0" 404 10174 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:01:53:54 +0200] "GET /User:Muriel24J11811 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:02:04:29 +0200] "GET /User:MyronP05439555 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - - [17/Apr/2026:02:19:35 +0200] "GET /User:MuoiBeacham4 HTTP/2.0" 404 10156 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:37:: - -
...
show less
Web Spam
Bad Web Bot