🇺🇸
TPI-Abuse
2026-09-14 06:13:56
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:13:48.707532 2026] [security2:error] [pid 31457:tid 31457] [client 47.79.200.168:24504] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.riedmannfamily.com|F|2"] [data ".riedmannfamily.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.riedmannfamily.com"] [uri "/riedmann-family-of-stetten-germany/www.riedmannfamily.com"] [unique_id "aqeQnL2RAV-PBZTig7vBlwAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-14 02:06:55
(8 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: elastic.sweetpuddingtrap.top | URI: /xmlrpc.php | UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
psauxit
2026-09-13 23:08:39
(11 hours ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-13 22:03:23
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:03:16.193866 2026] [security2:error] [pid 28298:tid 28298] [client 47.79.200.168:7220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.owenbee.com|F|2"] [data ".owenbee.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.owenbee.com"] [uri "/NewOwenBee/may-18-2025/www.owenbee.com"] [unique_id "aqcdpKHwOe3r0RiUOWZmaQAAABI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
1gz
2026-09-13 20:01:49
(15 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /kerko.php
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 16:04:03
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:03:55.782621 2026] [security2:error] [pid 25894:tid 25894] [client 47.79.200.168:59520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.imagesbyaubrey.com|F|2"] [data ".breezesys.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.imagesbyaubrey.com"] [uri "/obernai/www.breezesys.com"] [unique_id "aqbJa0QTH0Gi-TrNLnS2DAAAAAA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
1gz
2026-09-13 14:00:07
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/rindizet
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 19:01:57
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 15:01:52.324462 2026] [security2:error] [pid 11220:tid 11220] [client 47.79.200.168:41516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jackandmaxk.com|F|2"] [data ".jackandmaxk.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jackandmaxk.com"] [uri "/www.jackandmaxk.com"] [unique_id "aqWhoMaGi1_ltLATja-vGwAAAA8"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 13:01:32
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:01:26.520146 2026] [security2:error] [pid 7229:tid 7229] [client 47.79.200.168:46968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.markthwaite.com|F|2"] [data ".bauhausmusik.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.markthwaite.com"] [uri "/www.bauhausmusik.com"] [unique_id "aqVNJuN9o90Z9SwtiFp2aQAAABg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
conseilgouz
2026-09-12 10:00:25
(2 days ago)
loe-7 : Trying access unauthorized files/dir=>/kunena/bgmax/27-adaptation-pour-template-vertex-de-sh ...
show more
loe-7 : Trying access unauthorized files/dir=>/kunena/bgmax/27-adaptation-pour-template-vertex-de-shape-5
show less
Hacking
🇹🇷
oalver
2026-09-12 04:51:49
(2 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-admin/media-upload.php?chromeless=1 (HTTP 500). First seen: 2026-09-11. Risk score: 30/100.
show less
Web App Attack
🇺🇸
webgobe
2026-09-11 23:04:18
(2 days ago)
wew-Joomla User : try to access forms...
Hacking
🇩🇪
Vegascosmetics
2026-09-11 21:09:43
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 71>=65, Abuse 72, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 19:18:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.200.168 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:18:41.239302 2026] [security2:error] [pid 11888:tid 11888] [client 47.79.200.168:42814] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.creartest.com|F|2"] [data ".casiangelesterceratemporada.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.creartest.com"] [uri "/www.casiangelesterceratemporada.com"] [unique_id "aqRUEb0bKXDXNAulTTcEBwAAAAs"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 16:11:44
(3 days ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /category/international | 2026-09-10 16:11 UTC
show less
Bad Web Bot