๐บ๐ธ
TPI-Abuse
2026-03-15 12:18:26
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 08:18:21.237388 2026] [security2:error] [pid 30787:tid 30787] [client 2a03:2880:f806:7:::49971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cerrovictoria.com"] [uri "/WordPress/wp-content/uploads/alti-watermark.old.htaccess"] [unique_id "abajjV4-AUM7-Mpum9MEFwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 11:57:00
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 07:56:53.395410 2026] [security2:error] [pid 24545:tid 24545] [client 2a03:2880:f806:7:::56107] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.bahamascruisersguide.com|F|2"] [data ". capesantamaria.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.bahamascruisersguide.com"] [uri "/Cruising-Info/page18/www. capesantamaria.com"] [unique_id "abaehVE0h-eperEgK7PRTgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 10:44:13
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 06:44:05.712637 2026] [security2:error] [pid 1933:tid 1933] [client 2a03:2880:f806:7:::42833] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "abaNdWmHrb9hI44bAKjxQAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 09:25:20
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 05:25:15.565135 2026] [security2:error] [pid 26731:tid 26731] [client 2a03:2880:f806:7:::50509] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.esysapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.esysapps.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "abZ6-1OOqYCvNGb-Lj0nAgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 08:41:48
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 04:41:42.254765 2026] [security2:error] [pid 28301:tid 28301] [client 2a03:2880:f806:7:::53625] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kclawoffice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kclawoffice.com"] [uri "/kclawoffice.com"] [unique_id "abZwxn33bLh420np1A6-WgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-03-15 01:57:01
(5 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐จ๐ฟ
antihack.anarchista.xyz
2026-03-15 00:49:01
(5 months ago)
404 burst: 30 hits in 10 min, URI /esej-europa-a-narody-odkial-a-kam/, Ref , UA meta-externalagent/1 ...
show more
404 burst: 30 hits in 10 min, URI /esej-europa-a-narody-odkial-a-kam/, Ref , UA meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
show less
Brute-Force
Web App Attack
Bad Web Bot
๐บ๐ธ
myagent.site
2026-03-14 20:54:33
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-14 16:00:07
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 12:00:00.640086 2026] [security2:error] [pid 22482:tid 22482] [client 2a03:2880:f806:7:::51047] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jamroomrecording.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jamroomrecording.com"] [uri "/jamroomrecording.com"] [unique_id "abWGAFLVljaC18cdO2fTuwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-13 19:04:42
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-13 00:43:58
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 20:43:54.834402 2026] [security2:error] [pid 504128:tid 504128] [client 2a03:2880:f806:7:::25309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "needtoorder.us"] [uri "/USE-To-BLOCKwww.countryipblocks.net.htaccess"] [unique_id "abNdytSsuhLZT6GDO2QHgQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 23:26:25
(5 months ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 19:26:17.467531 2026] [security2:error] [pid 10612:tid 10612] [client 2a03:2880:f806:7:::50547] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/nav.php"] [unique_id "abH6GaJ84y3kBq050LLGxQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-03-11 02:52:23
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-09 22:04:00
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:7:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 18:03:54.465964 2026] [security2:error] [pid 13826:tid 13826] [client 2a03:2880:f806:7:::24703] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||darkalleyproductions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "darkalleyproductions.com"] [uri "/darkalleyproductions.com"] [unique_id "aa9DyoyZQkJCxVH-up00agAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mrcrassi
2026-03-08 22:36:07
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/botao-manual-botao-onde-encontrar-central-universal/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot