๐ท๐บ
Mga Admin
2026-09-22 12:29:37
(6 hours ago)
47.109.67.33 - - [22/Sep/2026:19:29:37 +0700] "GET / HTTP/1.1" 403 7620 "-" "Mozilla/5.0 (iPhone; CP ...
show more
47.109.67.33 - - [22/Sep/2026:19:29:37 +0700] "GET / HTTP/1.1" 403 7620 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1"
...
show less
Web App Attack
๐ต๐ฑ
mscode.pl
2026-09-22 12:23:21
(7 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
ASN: 37963 (Hangzhou Alibaba ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
ASN: 37963 (Hangzhou Alibaba Advertising Co.,Ltd.)
Protocol: HTTP/1.1 (GET method)
Zone: mscode.pl
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
show less
Bad Web Bot
Anonymous
2026-09-22 09:26:35
(9 hours ago)
FortiWeb WAF: 36 attacks detected. Threat Score: 8200. Types: Client Management(18), GEO IP(18). Ori ...
show more
FortiWeb WAF: 36 attacks detected. Threat Score: 8200. Types: Client Management(18), GEO IP(18). Origin: China.
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-22 08:51:07
(10 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2026-09-22 07:29:09
(11 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Charlesiv
2026-09-21 22:00:46
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
ASN: 37963 (Hangzhou Alibaba ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
ASN: 37963 (Hangzhou Alibaba Advertising Co.,Ltd.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-21T21:12:54Z
Ray ID: a3ec121b191e5a75
UA: Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
show less
Bad Web Bot
๐บ๐ธ
gerensat
2026-09-21 16:16:45
(1 day ago)
2026-09-21 13:16:44 | / | [] | Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/ ...
show more
2026-09-21 13:16:44 | / | [] | Mozilla/5.0 (iPhone; CPU iPhone OS 13_2_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Mobile/15E148 Safari/604.1
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:43:36
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:43:29.946384 2026] [security2:error] [pid 25156:tid 25156] [client 47.109.67.33:47818] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||bikiniwatersports.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bikiniwatersports.com"] [uri "/"] [unique_id "arFCkbG1TcrRb1-GM0U9aAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
flaus
2026-09-21 11:32:47
(1 day ago)
$f2bV_matches
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:53:38
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:53:35.406504 2026] [security2:error] [pid 1754:tid 1754] [client 47.109.67.33:46760] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.arlan-associates.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.arlan-associates.com"] [uri "/"] [unique_id "arBx__EKmOxPIrmduFR-ugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 16:41:22
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 12:41:17.246563 2026] [security2:error] [pid 319:tid 319] [client 47.109.67.33:32924] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||iacarbonell.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "iacarbonell.com"] [uri "/"] [unique_id "arAMrau5nmDuaJIDdyjqWwAAABE"], referer: http://iacarbonell.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:50:54
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:50:47.765575 2026] [security2:error] [pid 9949:tid 9949] [client 47.109.67.33:58834] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||owenmail.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "owenmail.com"] [uri "/"] [unique_id "aq_yx7gQVSkj45hyOkemcgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:11:16
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:11:09.657316 2026] [security2:error] [pid 13096:tid 13096] [client 47.109.67.33:47110] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||ketsuri.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ketsuri.com"] [uri "/"] [unique_id "aq_pfa5EMG-rionNKkKjQwAAAAU"], referer: http://ketsuri.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:18:11
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:18:05.668790 2026] [security2:error] [pid 22050:tid 22050] [client 47.109.67.33:35906] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fritsknuf.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fritsknuf.com"] [uri "/blog/"] [unique_id "aq_dDfIL5t1XzbmocKfq9AAAABc"], referer: http://knufrarebooks.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:38:30
(2 days ago)
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 47.109.67.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:38:27.392934 2026] [security2:error] [pid 3105:tid 3105] [client 47.109.67.33:37388] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||biomechanicalwars.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "biomechanicalwars.com"] [uri "/"] [unique_id "aq_Twxnf4DTC7Gz0kZrtZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack