Anonymous
2026-06-13 09:27:29
(7 hours ago)
FortiWeb WAF: 42 attacks detected. Threat Score: 14200. Types: Client Management(21), GEO IP(21). Or ...
show more
FortiWeb WAF: 42 attacks detected. Threat Score: 14200. Types: Client Management(21), GEO IP(21). Origin: Singapore.
show less
Web App Attack
πΊπΈ
kosada.com
2026-06-13 00:24:57
(16 hours ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
π«π·
Sklurk
2026-06-12 18:31:46
(22 hours ago)
Web App Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 13:17:40
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 09:17:35.044691 2026] [security2:error] [pid 26944:tid 26944] [client 47.79.205.234:58038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.3905ccn.org|F|2"] [data ".qrz.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.3905ccn.org"] [uri "/\\\\\\\\www.qrz.com"] [unique_id "aiwG7-JV73tOw-8mBaPjqwAAAA0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 21:01:47
(1 day ago)
(mod_security) mod_security (id:210381) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210381) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 17:01:43.056987 2026] [security2:error] [pid 13172:tid 13183] [client 47.79.205.234:34430] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisiana18wheeleraccidentlawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisiana18wheeleraccidentlawyer/%url%"] [unique_id "aisiNxY2gzjhJkZeUMvwhQAAAAY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 12:19:16
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:19:12.311245 2026] [security2:error] [pid 16797:tid 16797] [client 47.79.205.234:25176] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.beirutbazar.com|F|2"] [data ".beirutbazar.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.beirutbazar.com"] [uri "/nstores/platform-39/www.beirutbazar.com"] [unique_id "aiqnwKNtvGbuZfkuSBJnpAAAAAE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 10:20:39
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 06:20:32.604576 2026] [security2:error] [pid 7241:tid 7241] [client 47.79.205.234:30156] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||johnmueller.org|F|2"] [data ".frankschaffer.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "johnmueller.org"] [uri "/Problems/www.frankschaffer.com"] [unique_id "aiqL8OSv0QZDt2H9stKQVwAAAAA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 09:31:51
(2 days ago)
FortiWeb WAF: 59 attacks detected. Threat Score: 6000. Types: GEO IP(30), Client Management(29). Ori ...
show more
FortiWeb WAF: 59 attacks detected. Threat Score: 6000. Types: GEO IP(30), Client Management(29). Origin: Singapore.
show less
Web App Attack
π¨π¦
1gz
2026-06-11 01:30:00
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/donaldi-mosha
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-10 21:13:12
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 17:13:07.455033 2026] [security2:error] [pid 24475:tid 24500] [client 47.79.205.234:17288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebiglies.net|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebiglies.net"] [uri "/ariel95.com"] [unique_id "ainTY961adZzAvn88UqkxwAAAJc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 15:32:18
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.205.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 11:32:13.616046 2026] [security2:error] [pid 19646:tid 19646] [client 47.79.205.234:49208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.beirutbazar.com|F|2"] [data ".beirutbazar.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.beirutbazar.com"] [uri "/item/christina-debs-initials-collection-usd-2285/www.beirutbazar.com"] [unique_id "adEu_ZoRknJnic5bSh35-gAAAAg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
librebit
2026-04-02 06:22:58
(2 months ago)
Brute force
Brute-Force
πΊπΈ
gui-ying233
2026-03-22 07:20:46
(2 months ago)
Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Sa ...
show more
Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
π«π·
Sklurk
2026-02-25 06:43:35
(3 months ago)
Web App Attack
Web App Attack
πΊπΈ
ersei.net
2026-01-29 21:09:16
(4 months ago)
Web app exploiting
Web App Attack