๐ซ๐ท
Sklurk
2026-06-12 21:15:13
(4 hours ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 10:35:49
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 06:35:46.201990 2026] [security2:error] [pid 31273:tid 31273] [client 47.79.206.149:50270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.flyingdodopublications.com|F|2"] [data ".egressstudiopress.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.flyingdodopublications.com"] [uri "/by-comic/herbert/www.egressstudiopress.com"] [unique_id "aivhArpwT6HWsJcN3_fjTAAAAAE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
1gz
2026-06-12 09:15:31
(16 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /lajme/marre-me-qira
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-06-12 05:32:02
(20 hours ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 05:30:34
(20 hours ago)
(mod_security) mod_security (id:210381) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210381) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 01:30:26.201724 2026] [security2:error] [pid 7835:tid 7853] [client 47.79.206.149:41110] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.lawyerlouisiana.com|F|4"] [data "REQUEST_URI=/%stripbasekeyword%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.lawyerlouisiana.com"] [uri "/%stripbasekeyword%"] [unique_id "aiuZchBAHhmJx7AUU8PIawAAAU0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 04:00:33
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 00:00:27.238951 2026] [security2:error] [pid 8510:tid 8510] [client 47.79.206.149:1466] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zackfranz.com|F|2"] [data ".perissosdigitalmarketing.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zackfranz.com"] [uri "/media.perissosdigitalmarketing.com"] [unique_id "aiuEW0jhOXTooK-zbeSehAAAABA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 12:04:17
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 08:04:11.023086 2026] [security2:error] [pid 14459:tid 14459] [client 47.79.206.149:32512] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gundiahgazette.com.au|F|2"] [data ".munnacreekhall.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gundiahgazette.com.au"] [uri "/www.munnacreekhall.com"] [unique_id "aiqkO1Wm3WjwAHOYaucMhwAAAA4"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 09:33:06
(1 day ago)
FortiWeb WAF: 55 attacks detected. Threat Score: 5600. Types: GEO IP(28), Client Management(27). Ori ...
show more
FortiWeb WAF: 55 attacks detected. Threat Score: 5600. Types: GEO IP(28), Client Management(27). Origin: Singapore.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 06:03:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 02:03:00.292494 2026] [security2:error] [pid 17937:tid 18071] [client 47.79.206.149:50480] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.linfoulk.org|F|2"] [data ".rkingmusic.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.linfoulk.org"] [uri "/home/hornandpiano/www.rkingmusic.com"] [unique_id "aipPlBQUHme0qAUtYRbf-AAAAQ0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-28 00:40:03
(2 months ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
ersei.net
2026-01-29 17:42:56
(4 months ago)
Web app exploiting
Web App Attack
๐บ๐ธ
ersei.net
2026-01-25 01:19:34
(4 months ago)
Web app exploiting
Web App Attack
๐ฎ๐น
VHosting
2026-01-08 11:36:25
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
ersei.net
2026-01-06 00:27:15
(5 months ago)
Nonstop scanning with no cooldown or respect for 429.
Bad Web Bot
๐บ๐ธ
kosada.com
2026-01-05 14:08:13
(5 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot