πΊπΈ
TPI-Abuse
2026-02-27 07:00:44
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 02:00:23.027502 2026] [security2:error] [pid 15305:tid 15305] [client 2a03:2880:f806:40:::51741] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rocky-ridgeco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rocky-ridgeco.com"] [uri "/rocky-ridgeco.com"] [unique_id "aaFBBhQ_TsRlXtzTcg_3lAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-26 02:20:21
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 21:20:13.604379 2026] [security2:error] [pid 18639:tid 18639] [client 2a03:2880:f806:40:::49145] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swindon-itf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swindon-itf.com"] [uri "/swindon-itf.com"] [unique_id "aZ-t3TqeFR0ROs1badJ5NgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-23 07:58:38
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 02:58:30.157975 2026] [security2:error] [pid 19823:tid 19823] [client 2a03:2880:f806:40:::34165] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jennlaurenphotography.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jennlaurenphotography.com"] [uri "/jennlaurenphotography.com"] [unique_id "aZwIpiMAjk0sLiiA_q06QwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-22 16:15:58
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 11:15:55.117758 2026] [security2:error] [pid 9583:tid 9583] [client 2a03:2880:f806:40:::61343] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grancanariaholidays.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grancanariaholidays.com"] [uri "/grancanariaholidays.com"] [unique_id "aZsru57yeOL-w4SXABNvIQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-20 17:34:03
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 12:33:55.712151 2026] [security2:error] [pid 2149:tid 2149] [client 2a03:2880:f806:40:::51617] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automationmp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automationmp.com"] [uri "/automationmp.com"] [unique_id "aZibA4bWEaeN8HoMbB07TQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
kranem
2025-12-04 03:00:08
(9 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK)
Protocol: HTTP/2 (GET me ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK)
Protocol: HTTP/2 (GET method)
Endpoint: /sitemap-index.xml
Timestamp: 2025-12-04T01:27:24Z
User-Agent: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-12-03 00:03:32
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 02 19:03:27.910860 2025] [security2:error] [pid 18972:tid 18972] [client 2a03:2880:f806:40:::59024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "aS9-T5TRZoBJKxAahL0qjwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2025-11-25 16:05:49
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /app-garen/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-11-21 17:05:46
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 12:05:39.632845 2025] [security2:error] [pid 25125:tid 25125] [client 2a03:2880:f806:40:::51552] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nesetsv.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nesetsv.com"] [uri "/nesetsv.com"] [unique_id "aSCb4_ypA3cGoIbMnZoDvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-21 15:10:30
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 10:10:23.279668 2025] [security2:error] [pid 25949:tid 25949] [client 2a03:2880:f806:40:::36774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edfisherco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edfisherco.com"] [uri "/edfisherco.com"] [unique_id "aSCA33BOI43D4_BpnX_U_QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-20 16:47:58
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 11:47:54.275514 2025] [security2:error] [pid 10189:tid 10189] [client 2a03:2880:f806:40:::55246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adonamusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adonamusic.com"] [uri "/adonamusic.com"] [unique_id "aR9GOsPB9VPmfwgMQgtsRQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2025-11-20 08:35:24
(9 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/kdz-tsi-pro-1-2/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π³π±
Roderic
2025-11-19 06:38:52
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-11-17 20:50:56
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 15:50:53.288168 2025] [security2:error] [pid 21937:tid 21937] [client 2a03:2880:f806:40:::57548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bjfrancislaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bjfrancislaw.com"] [uri "/bjfrancislaw.com"] [unique_id "aRuKrZhrPselP0pOfuqfXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-15 02:44:59
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:40:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 21:44:52.867972 2025] [security2:error] [pid 1425:tid 1425] [client 2a03:2880:f806:40:::37882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "aRfpJIAxCbekHCYYcbzNDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack