Anonymous
2026-04-24 01:27:30
(4 months ago)
(resource-exhaustion) Server-wide Bot Block Heavy URL: filter_ 2a03:2880:f806:3a:: (US/United States ...
show more
(resource-exhaustion) Server-wide Bot Block Heavy URL: filter_ 2a03:2880:f806:3a:: (US/United States/-)
show less
Hacking
๐บ๐ธ
gui-ying233
2026-04-24 00:22:50
(4 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-22 23:48:53
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 19:48:43.659487 2026] [security2:error] [pid 2918392:tid 2918392] [client 2a03:2880:f806:3a:::52294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "aeleW1UdFqiSMgEH4OAU9QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 04:54:00
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 00:53:54.545482 2026] [security2:error] [pid 22013:tid 22013] [client 2a03:2880:f806:3a:::45568] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leirstein.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leirstein.com"] [uri "/leirstein.com"] [unique_id "aehUYtIZ6PIdU3qnBUSapQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-04-21 19:04:18
(4 months ago)
Too many failed requests
2a03:2880:f806:3a:: - - [21/Apr/2026:19:38:49 +0200] "GET /User:DerrickBuck ...
show more
Too many failed requests
2a03:2880:f806:3a:: - - [21/Apr/2026:19:38:49 +0200] "GET /User:DerrickBuckner5 HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [21/Apr/2026:20:20:22 +0200] "GET /User:DickPendleton11 HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [21/Apr/2026:20:28:23 +0200] "GET /User:DonteClune621 HTTP/2.0" 404 10174 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [21/Apr/2026:20:33:14 +0200] "GET /User:Dora44O5873239 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [21/Apr/2026:20:36:28 +0200] "GET /User:DortheaA98 HTTP/2.0" 404 10120 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - -
...
show less
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-21 10:58:34
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 06:58:28.292484 2026] [security2:error] [pid 1161970:tid 1161970] [client 2a03:2880:f806:3a:::32516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||amazingwelding.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazingwelding.com"] [uri "/amazingwelding.com"] [unique_id "aedYVB3-5Byfq9rEn-ziJgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-18 20:26:14
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 16:26:10.768193 2026] [security2:error] [pid 3638197:tid 3638197] [client 2a03:2880:f806:3a:::52904] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rocky-ridgeco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rocky-ridgeco.com"] [uri "/rocky-ridgeco.com"] [unique_id "aePo4joj3MJeiyytqMKxbgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-18 12:30:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 08:30:07.436787 2026] [security2:error] [pid 1729901:tid 1729901] [client 2a03:2880:f806:3a:::42576] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||genevaatlantic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "genevaatlantic.com"] [uri "/genevaatlantic.com"] [unique_id "aeN5T_PGgLtk66loXQZ0LAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-18 07:26:20
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 03:26:14.009026 2026] [security2:error] [pid 52799:tid 52799] [client 2a03:2880:f806:3a:::39742] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||impostersyndromeunmasked.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "impostersyndromeunmasked.com"] [uri "/impostersyndromeunmasked.com"] [unique_id "aeMyFgii8Tlbjixflx2BCQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-04-17 22:56:45
(4 months ago)
Too many failed requests
2a03:2880:f806:3a:: - - [17/Apr/2026:20:57:48 +0200] "GET /User:CornellChri ...
show more
Too many failed requests
2a03:2880:f806:3a:: - - [17/Apr/2026:20:57:48 +0200] "GET /User:CornellChristman HTTP/2.0" 404 10228 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [17/Apr/2026:20:58:52 +0200] "GET /User:CorrineHailes30 HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [17/Apr/2026:22:00:08 +0200] "GET /index.php?title=Special:WhatLinksHere/Template:Item&limit=100&from=65484&back=65442&hidelinks=1&hidetrans=1 HTTP/2.0" 404 12371 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [17/Apr/2026:22:30:36 +0200] "GET /index.php?title=Special:WhatLinksHere/A_Ship%27s_Flag&limit=500&hidelinks=1 HTTP/2.0" 404 12230 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:3a:: - - [17/Apr/2026:23:01:46 +0200] "GET /User:Melv
...
show less
Web Spam
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-04-14 00:21:57
(4 months ago)
meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐ต๐ฑ
sefinek.net
2026-04-14 00:18:12
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /booru | UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler) โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-04-14 00:06:43
(4 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
myagent.site
2026-04-13 18:28:20
(4 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-13 17:18:39
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:3a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 13:18:29.849120 2026] [security2:error] [pid 4075843:tid 4075853] [client 2a03:2880:f806:3a:::35923] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.aafm.us|F|2"] [data ".gafm.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.aafm.us"] [uri "/www.GAFM.com"] [unique_id "ad0lZcrlP22S4ln3mO_XgAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack