|
๐ฆ๐บ
MAGIC
|
|
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
|
DDoS Attack
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 12:05:25.476823 2026] [security2:error] [pid 2251198:tid 2251198] [client 79.142.79.44:33337] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.blacksheepoffroad.com|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.blacksheepoffroad.com"] [uri "/license.txt"] [unique_id "adUrRWib7cJ0SBAwTxUPqQAAACk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 11:29:13.788583 2026] [security2:error] [pid 1378870:tid 1378870] [client 79.142.79.44:40299] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||bigheartskitchen.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "bigheartskitchen.net"] [uri "/license.txt"] [unique_id "adUiyTVBv_Giw3_PVJj_egAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 10:50:04.469055 2026] [security2:error] [pid 1175212:tid 1175212] [client 79.142.79.44:52987] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||bennefeld.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "bennefeld.net"] [uri "/license.txt"] [unique_id "adUZnJhgdx3n3LNSnujpqQAAAAY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 10:28:21.126766 2026] [security2:error] [pid 1220871:tid 1220871] [client 79.142.79.44:28034] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||beckerbrokerage.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "beckerbrokerage.net"] [uri "/license.txt"] [unique_id "adUUhScTXkw5mau2xGarQAAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 10:06:16.811666 2026] [security2:error] [pid 1149266:tid 1149266] [client 79.142.79.44:46867] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||bayareahiphopforever.org|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "bayareahiphopforever.org"] [uri "/license.txt"] [unique_id "adUPWBTfYE8UCpheZ8QlcAAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 09:46:21.361405 2026] [security2:error] [pid 1173411:tid 1173411] [client 79.142.79.44:26271] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||barabesi.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "barabesi.net"] [uri "/license.txt"] [unique_id "adUKrdPFfyyABfburDD7FwAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 09:20:02.468621 2026] [security2:error] [pid 1458275:tid 1458275] [client 79.142.79.44:39724] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||bacona.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "bacona.net"] [uri "/license.txt"] [unique_id "adUEguJ7R7PqchLqdJh8fAAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 09:01:34.876062 2026] [security2:error] [pid 1237178:tid 1237178] [client 79.142.79.44:8700] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||axiomemail.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "axiomemail.net"] [uri "/license.txt"] [unique_id "adUALsOJdmQrN5qjQwj2eAAAABw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 08:33:52.385624 2026] [security2:error] [pid 1065109:tid 1065109] [client 79.142.79.44:32533] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||aurumprivatecapital.com|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "aurumprivatecapital.com"] [uri "/"] [unique_id "adT5sC5MoMCqg-KzTy7angAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 08:14:51.887535 2026] [security2:error] [pid 1612507:tid 1612507] [client 79.142.79.44:61569] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||aticom.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "aticom.net"] [uri "/license.txt"] [unique_id "adT1O1b0fpx3_8QCSx2NegAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ฎ
as211431.net
|
|
Triggered Cloudflare WAF (firewallCustom) from CH.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1. ...
show more
Triggered Cloudflare WAF (firewallCustom) from CH.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /license.txt
UA: Mozilla/5.0 (Windows NT 5.1; rv:22.0) Gecko/20100101 Firefox/22.0 Paros/3.2.13
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 07:39:40.990662 2026] [security2:error] [pid 1066498:tid 1066498] [client 79.142.79.44:43450] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||arthuryeung.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "arthuryeung.net"] [uri "/license.txt"] [unique_id "adTs_GxeBJSydNdy2nUgcAAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 07:18:38.553105 2026] [security2:error] [pid 1224113:tid 1224113] [client 79.142.79.44:18479] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||ardath.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "ardath.net"] [uri "/license.txt"] [unique_id "adToDv-cikcK2jx3Cd1Q_wAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the las ...
show more
(mod_security) mod_security (id:210801) triggered by 79.142.79.44 (ch-net.as51430.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 07:03:22.570898 2026] [security2:error] [pid 2677001:tid 2677029] [client 79.142.79.44:4796] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||appraisalteam.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "appraisalteam.net"] [uri "/license.txt"] [unique_id "adTkeh2tGXX7f2HfX24JTAAAAJc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|