๐บ๐ธ
TPI-Abuse
2026-08-01 14:14:51
(8 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 10:14:45.303921 2026] [security2:error] [pid 569969:tid 569978] [client 2a09:bac5:4e25:270f::3e4:37:16316] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||ipv6.ace-es.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "ipv6.ace-es.com"] [uri "/"] [unique_id "am3_VcUts0Y2lkkgQSi25gAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 12:46:30
(9 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:46:23.432424 2026] [security2:error] [pid 2458806:tid 2458806] [client 2a09:bac5:4e25:270f::3e4:37:12096] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||technesa.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "technesa.com"] [uri "/"] [unique_id "am3qn0_3hXxtWLwcpgo4aQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 07:01:14
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:949110) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 03:01:10.692275 2026] [security2:error] [pid 1587696:tid 1587696] [client 2a09:bac5:4e25:270f::3e4:37:20648] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "gaming.freedrm.org"] [uri "/"] [unique_id "am2Ztgfjl9j_ed2RUIHoygAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-01 05:14:15
(17 hours ago)
2 attacks on PHP URLs, shell probes:
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1 ...
show more
2 attacks on PHP URLs, shell probes:
POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1
POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 05:12:43
(17 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 01:12:37.451200 2026] [security2:error] [pid 4270:tid 4270] [client 2a09:bac5:4e25:270f::3e4:37:21542] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||doll.handyrehab.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "doll.handyrehab.com"] [uri "/"] [unique_id "am2ARdl796akdua5oWuRGAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 02:14:20
(20 hours ago)
2a09:bac5:4e25:270f::3e4:37 - - [01/Aug/2026:02:14:20 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/ ...
show more
2a09:bac5:4e25:270f::3e4:37 - - [01/Aug/2026:02:14:20 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 461 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 01:12:28
(21 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:12:23.566774 2026] [security2:error] [pid 1057739:tid 1057739] [client 2a09:bac5:4e25:270f::3e4:37:41180] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||title27.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "title27.com"] [uri "/"] [unique_id "am1H92S5ZdevnhlQwlP4FwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 00:35:41
(21 hours ago)
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 20:35:33.641141 2026] [security2:error] [pid 3664330:tid 3664330] [client 2a09:bac5:4e25:270f::3e4:37:10434] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||periodpiano.org|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "periodpiano.org"] [uri "/"] [unique_id "am0_VR9PbZKTdRV5YsZgLwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 20:44:29
(1 day ago)
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:218420) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 16:44:21.223658 2026] [security2:error] [pid 3650167:tid 3650167] [client 2a09:bac5:4e25:270f::3e4:37:40944] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||maryrosevaro.com|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "maryrosevaro.com"] [uri "/"] [unique_id "am0JJbEy4TixqzaoAbPDkwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-31 20:04:38
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-cve-2021-41773
Web App Attack
Hacking
๐ซ๐ฎ
as211431.net
2026-07-31 02:36:49
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
SCHAPPY
2026-07-28 17:25:01
(4 days ago)
Rotating user agents detected to hide crawling or other malicious activitiy, blocked.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 21:04:43
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e25:270f::3e4:37 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 17:04:36.300805 2026] [security2:error] [pid 3631913:tid 3631980] [client 2a09:bac5:4e25:270f::3e4:37:37720] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alfred.merart.com|F|2"] [data ".js.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alfred.merart.com"] [uri "/dist/main.js.old"] [unique_id "amKB5JU8J-iQHoyeRuQrHwAAAYQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-07-23 17:53:10
(1 week ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
Charlesiv
2026-07-23 04:00:14
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 13335 (Cloudflare, Inc.) ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 13335 (Cloudflare, Inc.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-07-23T02:58:26Z
Ray ID: a1f76c639988199c
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15
show less
Bad Web Bot