๐บ๐ธ
TPI-Abuse
2026-10-01 15:55:54
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.159.25.221 (221.25.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.25.221 (221.25.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:55:47.860974 2026] [security2:error] [pid 3768:tid 3768] [client 34.159.25.221:51098] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||naturalhomebuilders.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "naturalhomebuilders.com"] [uri "/z9x8c7v6b5-debug-trigger-naturalhomebuilders.com"] [unique_id "ar6Cg8aigqDt0JapNIvrsAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:31:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.159.25.221 (221.25.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.25.221 (221.25.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:31:23.667539 2026] [security2:error] [pid 16542:tid 16542] [client 34.159.25.221:48424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pozzolan.org"] [uri "/web.config"] [unique_id "ar58yz_H-3kyTWM3uZG0igAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-01 15:14:23
(1 day ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 13:52:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.159.25.221 (221.25.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.25.221 (221.25.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:52:28.774988 2026] [security2:error] [pid 2695:tid 2695] [client 34.159.25.221:39932] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbg.banis-associates.com|F|2"] [data ".banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbg.banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-nbg.banis-associates.com"] [unique_id "ar5lnEBLgX8rnRTs34QBcAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-01 13:34:56
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-10-01 13:03:35
(1 day ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.nbmedical.gr; logs=/var/log/httpd/domains/nbmedical.gr.l ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.nbmedical.gr; logs=/var/log/httpd/domains/nbmedical.gr.log; samples=/cache/original/%2e%2e/%2e%2e/.env | /cache/original/%2e%2e/.env | /gcp-credentials.json
show less
Hacking
Web App Attack
Anonymous
2026-10-01 12:24:43
(1 day ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-10-01 12:22:20
(1 day ago)
Portscan: TCP/8080 (3x), TCP/8443 (3x)
Port Scan
๐ณ๐ฑ
Site.eu
2026-10-01 11:47:58
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
mrcrassi
2026-10-01 11:38:20
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from DE.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 10:40:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.159.25.221 (221.25.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.159.25.221 (221.25.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:40:02.965941 2026] [security2:error] [pid 15846:tid 15846] [client 34.159.25.221:59452] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.indie100.com|F|2"] [data ".indie100.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.indie100.com"] [uri "/z9x8c7v6b5-debug-trigger-nbcnewsradio.indie100.com"] [unique_id "ar44gnfQci62NaQlsDWnNQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 09:59:19
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-10-01 09:54:22
(1 day ago)
XSS Attempt
Hacking
๐บ๐ธ
jormaster3k
2026-10-01 09:20:09
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-01 09:13:31
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.159.25.221 (DE/Germany/221.25.159.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.159.25.221 (DE/Germany/221.25.159.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack