Anonymous
2026-06-11 14:38:18
(4 hours ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 14:08:12
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 10:08:09.050507 2026] [security2:error] [pid 10568:tid 10582] [client 47.79.201.35:30626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||baronlongford.com|F|2"] [data ".fiefblondel.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "baronlongford.com"] [uri "/www.FiefBlondel.com"] [unique_id "airBSTyhddIUGdRg6MffIgAAAIo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 01:11:14
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 21:11:06.957474 2026] [security2:error] [pid 5825:tid 5825] [client 47.79.201.35:30504] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.beirutbazar.com|F|2"] [data ".bymargherita.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.beirutbazar.com"] [uri "/sellers/margherita/www.bymargherita.com"] [unique_id "aioLKuENr4Ty6Pu0q-amiAAAABE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 00:21:54
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 20:21:47.287593 2026] [security2:error] [pid 2106:tid 2115] [client 47.79.201.35:46746] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||behaviorhealth.org|F|2"] [data ".barnesandnoble.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "behaviorhealth.org"] [uri "/www.BarnesandNoble.com"] [unique_id "ain_m99-qDMorbNbBUiJjwAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 16:11:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 12:11:08.074875 2026] [security2:error] [pid 22638:tid 22638] [client 47.79.201.35:21832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tonytremblayauthor.com|F|2"] [data ".tonytremblayauthor.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tonytremblayauthor.com"] [uri "/www.tonytremblayauthor.com"] [unique_id "aimMnP5pwbhAFIdWS_9AqwAAAA0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-03-29 02:16:58
(2 months ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0
show less
Bad Web Bot
๐จ๐ฆ
1gz
2026-03-29 02:13:57
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lexo.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-03-21 00:18:47
(2 months ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0
show less
Bad Web Bot
๐บ๐ธ
SSH-Admin
2026-01-19 01:55:19
(4 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐บ๐ธ
ersei.net
2026-01-16 03:04:39
(4 months ago)
Nonstop scanning with no cooldown or respect for 429.
Bad Web Bot
๐ซ๐ท
Sklurk
2026-01-15 15:09:26
(4 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
kosada.com
2026-01-06 12:07:39
(5 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2025-12-27 15:42:41
(5 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
ersei.net
2025-12-14 08:45:29
(5 months ago)
Nonstop scanning with no cooldown or respect for 429.
Bad Web Bot
๐ซ๐ท
Sklurk
2025-12-13 02:41:39
(5 months ago)
Web App Attack
Web App Attack