πΊπΈ
TPI-Abuse
2026-03-15 04:31:57
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 00:31:51.346565 2026] [security2:error] [pid 18553:tid 18553] [client 2a03:2880:f806:d:::56539] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||book-arts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "book-arts.com"] [uri "/book-arts.com"] [unique_id "abY2N95BcqRgeh8iaXj_2wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 17:57:10
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 13:57:03.022429 2026] [security2:error] [pid 20345:tid 20345] [client 2a03:2880:f806:d:::54367] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jennlaurenphotography.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jennlaurenphotography.com"] [uri "/jennlaurenphotography.com"] [unique_id "abWhb1qpTuWJk3lZeTDsPgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 16:16:45
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 12:16:40.114638 2026] [security2:error] [pid 5457:tid 5457] [client 2a03:2880:f806:d:::26007] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "abWJ6MXYJP0oos_MaLgEwQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-12 23:22:25
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 19:22:17.983659 2026] [security2:error] [pid 24963:tid 24963] [client 2a03:2880:f806:d:::21531] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellamazing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellamazing.com"] [uri "/mitchellamazing.com"] [unique_id "abNKqcDNUeoAThqFc5EV4wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-11 00:52:19
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 20:52:13.508132 2026] [security2:error] [pid 3950:tid 3950] [client 2a03:2880:f806:d:::56235] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||microscopedia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "microscopedia.com"] [uri "/microscopedia.com"] [unique_id "abC8vfXdGE1ZMNTNCf2nGwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-09 21:37:54
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 17:37:48.214203 2026] [security2:error] [pid 17055:tid 17140] [client 2a03:2880:f806:d:::32215] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stone-doyle.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stone-doyle.com"] [uri "/stone-doyle.com"] [unique_id "aa89rJne3SOJB6eEYbo_ogAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
mrcrassi
2026-03-09 02:57:12
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /produto/pivo-duo-simples-1-4/
UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
myagent.site
2026-03-08 22:19:52
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking
πΊπΈ
TPI-Abuse
2026-03-07 20:07:19
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 07 15:07:13.570953 2026] [security2:error] [pid 17254:tid 17254] [client 2a03:2880:f806:d:::63609] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertautoworks.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "aayFcdEYBbe0K0zh5uB6RQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-07 04:47:11
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 06 23:47:06.230001 2026] [security2:error] [pid 22368:tid 22368] [client 2a03:2880:f806:d:::60891] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.glamorgirl.net|F|2"] [data ".wickedpictures.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.glamorgirl.net"] [uri "/news/www.wickedpictures.com"] [unique_id "aautyr9sDej6HR85BvZSvgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-02 20:10:21
(6 months ago)
(mod_security) mod_security (id:211010) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:211010) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 15:10:04.807762 2026] [security2:error] [pid 12715:tid 12715] [client 2a03:2880:f806:d:::29731] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/antidisestablishmentarianism" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "38"] [id "211010"] [rev "1"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||mail.computerian.net|F|1"] [data "/store/antidisestablishmentarianism/milligal77078181252.html"] [severity "ALERT"] [tag "CWAF"] [tag "Agents"] [hostname "mail.computerian.net"] [uri "/store/antidisestablishmentarianism/milligal77078181252.html"] [unique_id "aaXunFF8BgG7HT5rH68LSAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-26 03:09:21
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 22:09:13.645420 2026] [security2:error] [pid 19482:tid 19484] [client 2a03:2880:f806:d:::41873] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||missalastages.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "missalastages.com"] [uri "/missalastages.com"] [unique_id "aZ-5WYt3VuLYC10adc3YPgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-19 15:45:48
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 10:45:43.545051 2026] [security2:error] [pid 28332:tid 28332] [client 2a03:2880:f806:d:::29507] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jnpmarinesolutions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jnpmarinesolutions.com"] [uri "/jnpmarinesolutions.com"] [unique_id "aZcwJ2hkFWOhuzfet8P6FwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-16 02:27:45
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 21:27:38.665334 2026] [security2:error] [pid 8005:tid 8005] [client 2a03:2880:f806:d:::23775] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automationmp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automationmp.com"] [uri "/automationmp.com"] [unique_id "aZKAmr-ZqC3VEFQ5pjEJkwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-15 05:53:20
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:d:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:53:15.744992 2026] [security2:error] [pid 450316:tid 450343] [client 2a03:2880:f806:d:::53311] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||businessbasicsinstitute.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "businessbasicsinstitute.com"] [uri "/businessbasicsinstitute.com"] [unique_id "aZFfSx0sx_eeMebJ82NxRAAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack