🇺🇸
TPI-Abuse
2026-09-14 07:08:29
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 03:08:21.412368 2026] [security2:error] [pid 6319:tid 6319] [client 47.79.206.183:4102] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.imagesbyaubrey.com|F|2"] [data ".breezesys.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.imagesbyaubrey.com"] [uri "/ceskykrumlov/www.breezesys.com"] [unique_id "aqedZSLtRutqXA4VMf9JWAAAAAA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 04:08:51
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:08:44.648682 2026] [security2:error] [pid 19627:tid 19627] [client 47.79.206.183:17742] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ismaelcavazos.com|F|2"] [data ".ismaelcavazos.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ismaelcavazos.com"] [uri "/tag/altcoin/www.ismaelcavazos.com"] [unique_id "aqdzTD8ZCN9Di1dbo5FRpQAAAAQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 03:05:59
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 23:05:53.125575 2026] [security2:error] [pid 27334:tid 27334] [client 47.79.206.183:30682] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kadinisi.org|F|2"] [data ".instagram.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kadinisi.org"] [uri "/basari-hikayeleri/yarim-kalan-yolculuktan-yeni-bir-baslangica-nancy-kafaoglu/www.instagram.com"] [unique_id "aqdkkbqBG_sxDLjsmiWs8AAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
jbcrn
2026-09-13 16:11:47
(16 hours ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deflagration.by-Anableps. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
show less
Bad Web Bot
Web App Attack
🇺🇸
1gz
2026-09-13 16:07:29
(16 hours ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 09:12:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:12:12.315273 2026] [security2:error] [pid 28909:tid 28909] [client 47.79.206.183:64484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||francoiseroy.com|F|2"] [data ".cuartoamarillo.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "francoiseroy.com"] [uri "/www.cuartoamarillo.com"] [unique_id "aqUXbA3E25-HQoe8EhVVcgAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
conseilgouz
2026-09-12 09:10:56
(1 day ago)
loe-7 : Trying access unauthorized files/dir=>/forum/lm-prism/382-lm-prism-pas-de-coloration-pas-de- ...
show more
loe-7 : Trying access unauthorized files/dir=>/forum/lm-prism/382-lm-prism-pas-de-coloration-pas-de-bloc
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-12 02:12:36
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 22:12:30.838980 2026] [security2:error] [pid 26294:tid 26294] [client 47.79.206.183:58446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||smogsandiego.com|F|2"] [data ".starsmogsandiego.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smogsandiego.com"] [uri "/www.STARSmogSanDiego.com"] [unique_id "aqS1Dl-b0b232UQreMqmwQAAABQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-11 22:01:07
(2 days ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /drapeaux-prussiens-guerre-de-7-ans-par-frederic-aubert/kompagniefahne_ir10 | 2026-09-11 22:01 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 12:03:12
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 08:03:07.981480 2026] [security2:error] [pid 13525:tid 13525] [client 47.79.206.183:4148] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.americanureport.com|F|2"] [data ".americanureport.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.americanureport.com"] [uri "/tag/patriot-league/www.americanureport.com"] [unique_id "aqKcewouiIaAuflbYXwRdgAAAAg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 12:00:53
(3 days ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /feed | 2026-09-10 12:00 UTC
show less
Bad Web Bot
🇫🇷
conseilgouz
2026-09-10 11:13:59
(3 days ago)
saw-Joomla User : try to access forms...
Hacking
🇺🇸
TPI-Abuse
2026-09-09 22:04:42
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 18:04:35.084923 2026] [security2:error] [pid 2989:tid 2989] [client 47.79.206.183:6250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.peterjohnsonauthor.com|F|2"] [data ".peterjohnsonauthor.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.peterjohnsonauthor.com"] [uri "/www.peterjohnsonauthor.com"] [unique_id "aqHX8zEI_rWgWpBk-VpucwAAAAg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 15:02:28
(4 days ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /.well-known/nodeinfo | 2026-09-09 15:02 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 07:06:02
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:05:55.426249 2026] [security2:error] [pid 7691:tid 7691] [client 47.79.206.183:16938] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mirandaracewalks.com|F|2"] [data ".usa-homegym.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mirandaracewalks.com"] [uri "/www.usa-homegym.com"] [unique_id "ap-z0xwRIiZnF_benTiJDAAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack