๐ญ๐บ
kranem
2026-03-16 06:02:16
(6 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protoco ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-03-16T03:04:17Z
User-Agent: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 19:38:56
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 15:38:47.926121 2026] [security2:error] [pid 24244:tid 24244] [client 2a03:2880:f806:46:::31695] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||napaautopartskeokuk.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "napaautopartskeokuk.com"] [uri "/napaautopartskeokuk.com"] [unique_id "abcKxzsFFFJYvtFU7pRRywAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 16:49:06
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 12:49:02.563465 2026] [security2:error] [pid 14885:tid 14885] [client 2a03:2880:f806:46:::51211] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||microscopedia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "microscopedia.com"] [uri "/microscopedia.com"] [unique_id "abbi_g9PTEiZGILEVA0fDQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
kranem
2026-03-15 15:00:10
(6 months ago)
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protoco ...
show more
Triggered Cloudflare WAF from US.
Action taken: BLOCK
ASN: 32934 (FACEBOOK - Facebook, Inc.)
Protocol: HTTP/2 (GET method)
Endpoint: /SiteMap.aspx
Timestamp: 2026-03-15T14:57:20Z
User-Agent: meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-15 13:22:35
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 09:22:31.771429 2026] [security2:error] [pid 5075:tid 5075] [client 2a03:2880:f806:46:::23181] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||3-6trucking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3-6trucking.com"] [uri "/3-6trucking.com"] [unique_id "abaylwu0uBH501UBDaStKgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
BSG Webmaster
2026-03-15 11:05:37
(6 months ago)
Hacking Attempt using path /sitemap.txt
Brute-Force
Web App Attack
Anonymous
2026-03-15 09:02:40
(6 months ago)
(metabot_custom) Bloqueo de Meta Bot por exceso de hits (match: meta-externalagent/1.1 (+https://dev ...
show more
(metabot_custom) Bloqueo de Meta Bot por exceso de hits (match: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) 2a03:2880:f806:46:: (US/United States/-)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-15 06:44:54
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 02:44:47.027093 2026] [security2:error] [pid 10930:tid 10956] [client 2a03:2880:f806:46:::23335] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||charteredwealthmanager.com|F|2"] [data ".gafm.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "charteredwealthmanager.com"] [uri "/www.GAFM.com"] [unique_id "abZVX-52SfYp-qyqAo8RTAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 05:43:47
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 01:43:39.925159 2026] [security2:error] [pid 20238:tid 20238] [client 2a03:2880:f806:46:::46071] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "abZHCzV-YgR8eTbSJkr_nQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mehmet_The_Script_Kiddie
2026-03-15 02:45:36
(6 months ago)
CloudFlare WAF REPORT: Disobey robots.txt. Suspicious web crawler.
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-03-14 23:34:44
(6 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
myagent.site
2026-03-14 22:11:36
(6 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-14 21:21:28
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 17:21:23.634268 2026] [security2:error] [pid 26631:tid 26631] [client 2a03:2880:f806:46:::41433] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||natchezbicycle.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "natchezbicycle.com"] [uri "/natchezbicycle.com"] [unique_id "abXRU6srHqy9MHi4kwTkogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 20:50:27
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 16:50:21.218424 2026] [security2:error] [pid 32661:tid 32661] [client 2a03:2880:f806:46:::31761] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockwaychiropractic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockwaychiropractic.com"] [uri "/rockwaychiropractic.com"] [unique_id "abXKDQPiC-M3Pyx2z4ox2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 20:25:05
(6 months ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:46:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 16:24:56.889546 2026] [security2:error] [pid 22237:tid 22237] [client 2a03:2880:f806:46:::39003] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/nav.php"] [unique_id "abXEGAcADf1yQ0at--KAUgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack