๐บ๐ธ
1gz
2026-09-15 01:14:44
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /english/qmk
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
1gz
2026-09-14 06:13:57
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
jbcrn
2026-09-14 02:07:00
(2 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Disguised bots, ruleset: faked-browser. Requested honeypot path: /deadishness-preventively. User-Agent: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-13 14:00:13
(2 days ago)
Walking a list of paths that do not exist (scanning) | method: GET | path: /vide-greniers | 2026-09- ...
show more
Walking a list of paths that do not exist (scanning) | method: GET | path: /vide-greniers | 2026-09-13 14:00 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 18:01:49
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:01:42.839567 2026] [security2:error] [pid 3482:tid 3482] [client 47.79.207.247:62004] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||matrixpercussiontrio.com|F|2"] [data ".innovativepercussion.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "matrixpercussiontrio.com"] [uri "/www.innovativepercussion.com"] [unique_id "aqWThnBRpFI-P7s4IHcZrwAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 15:04:36
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 11:04:30.717674 2026] [security2:error] [pid 28448:tid 28448] [client 47.79.207.247:65534] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jdeloa.com|F|2"] [data ".jdeloa.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jdeloa.com"] [uri "/www.jdeloa.com"] [unique_id "aqVp_vA3GZdSsVzILGcvXQAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 14:13:57
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 10:13:50.066490 2026] [security2:error] [pid 1827:tid 1827] [client 47.79.207.247:11600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.peterjohnsonauthor.com|F|2"] [data ".peterjohnsonya.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.peterjohnsonauthor.com"] [uri "/shot-a-novel-in-short-stories-just-published/www.peterjohnsonya.com"] [unique_id "aqVeHokO404bvD022Thp7AAAAAk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
1gz
2026-09-12 14:09:03
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /english/simiq
UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ญ
flaus
2026-09-12 03:04:36
(4 days ago)
$f2bV_matches
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-12 02:04:11
(4 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (62, Abuse: 54)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 01:12:09
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:12:01.163210 2026] [security2:error] [pid 21160:tid 21169] [client 47.79.207.247:61266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockabyecotons.com|F|2"] [data ".orvis.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockabyecotons.com"] [uri "/cheers/references-resources-and-recommendations/www.orvis.com"] [unique_id "aqSm4TwAYkii9guuzk5mkAAAAIQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-11 17:06:42
(4 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /drapeaux-prussiens-guerre-de-7-ans-par-frederic-aubert/kompagniefahne_ir27 | 2026-09-11 17:06 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-10 14:01:57
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.207.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 10:01:51.435059 2026] [security2:error] [pid 23640:tid 23640] [client 47.79.207.247:18250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.livingminimal.com|F|2"] [data ".livingminimal.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.livingminimal.com"] [uri "/2020/08/www.livingminimal.com"] [unique_id "aqK4T7_A3U4TIo420TV5lgAAABA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
technojoe99
2026-09-10 05:04:27
(6 days ago)
Exploit scan from 47.79.207.247. GET /www.viddler.com HTTP/1.1.
Web App Attack
๐ฉ๐ช
LRob
2026-09-10 03:15:09
(6 days ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /film/exit-8 | 2026-09-10 03:15 UTC
show less
Bad Web Bot