๐ฒ๐พ
Rizzy
2026-10-02 14:28:33
(17 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-10-02 06:58:58
(1 day ago)
82.156.123.104 - - [02/Oct/2026:07:58:56 +0100] "GET /Framework/ThinkPHP.php HTTP/1.1" 404 6447 "htt ...
show more
82.156.123.104 - - [02/Oct/2026:07:58:56 +0100] "GET /Framework/ThinkPHP.php HTTP/1.1" 404 6447 "https://trailrides-wales.com/Framework/ThinkPHP.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
82.156.123.104 - - [02/Oct/2026:07:58:56 +0100] "GET /public/plugins/ckeditor/images/spacer.gif HTTP/1.1" 404 6447 "https://trailrides-wales.com/public/plugins/ckeditor/images/spacer.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
82.156.123.104 - - [02/Oct/2026:07:58:56 +0100] "GET /public/plugins/Ueditor/dialogs/attachment/images/alignicon.gif HTTP/1.1" 404 6447 "https://trailrides-wales.com/public/plugins/Ueditor/dialogs/attachment/images/alignicon.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:18:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:18:06.355526 2026] [security2:error] [pid 10825:tid 10825] [client 82.156.123.104:58982] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.barreda.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.barreda.org"] [uri "/okok.cer"] [unique_id "ar8-jlJHPXw3iaaEcvgUAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 04:07:03
(1 day ago)
Automated web scanner. Requested suspicious paths: /Framework/ThinkPHP.php. UTC: 2026-10-02 03:56:36 ...
show more
Automated web scanner. Requested suspicious paths: /Framework/ThinkPHP.php. UTC: 2026-10-02 03:56:36.
show less
Web App Attack
๐บ๐ธ
deskpass.com
2026-10-01 21:17:24
(1 day ago)
GET /Framework/ThinkPHP.php
Web App Attack
๐บ๐ธ
kosada.com
2026-10-01 08:40:12
(1 day ago)
Repeated requests for suspicious nonexistent URLs, for example: /public/ui/met/images/dt-9.gif (HTTP ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /public/ui/met/images/dt-9.gif (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:21:43
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:21:37.613296 2026] [security2:error] [pid 9514:tid 9514] [client 82.156.123.104:33090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vibratingharvard.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vibratingharvard.com"] [uri "/okok.cer"] [unique_id "ar21oS7__YTEcfC_CspZ5AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:11:58
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:11:49.087540 2026] [security2:error] [pid 31644:tid 31644] [client 82.156.123.104:37706] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shawnlayne.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shawnlayne.com"] [uri "/okok.cer"] [unique_id "aryMBdLZd-UQO3qPXtPGwwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pearbright
2026-09-29 22:43:06
(3 days ago)
82.156.123.104 - - [29/Sep/2026:22:43:01 +0000] "GET /public/ui/met/images/dt-9.gif HTTP/1.1" 404 50 ...
show more
82.156.123.104 - - [29/Sep/2026:22:43:01 +0000] "GET /public/ui/met/images/dt-9.gif HTTP/1.1" 404 500 "http://pearbright.com/public/ui/met/images/dt-9.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
82.156.123.104 - - [29/Sep/2026:22:43:01 +0000] "GET /README.md HTTP/1.1" 404 500 "http://pearbright.com/README.md" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
82.156.123.104 - - [29/Sep/2026:22:43:02 +0000] "GET /Framework/ThinkPHP.php HTTP/1.1" 404 500 "http://pearbright.com/Framework/ThinkPHP.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
82.156.123.104 - - [29/Sep/2026:22:43:02 +0000] "GET /e/DownSys/play/images/top_l.gif HTTP/1.1" 404 500 "http://pearbright.com/e/DownSys/play/images/top_l.gif" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Ch
...
show less
Web App Attack
Anonymous
2026-09-29 19:51:48
(3 days ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:02:56
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:02:52.437731 2026] [security2:error] [pid 11355:tid 11355] [client 82.156.123.104:33456] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mvpbees.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mvpbees.com"] [uri "/okok.cer"] [unique_id "arsALIrK-oNT5ocp8_4uugAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-28 17:15:36
(4 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
1gz
2026-09-28 13:57:12
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /dayrui/Fcms/Readme.txt
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-28 04:03:00
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 82.156.123.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 00:02:53.694460 2026] [security2:error] [pid 25398:tid 25398] [client 82.156.123.104:54420] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||linnardfinancial.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "linnardfinancial.com"] [uri "/okok.cer"] [unique_id "arnm7VV-6IOF1ssS2rwK8QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NRVDigital
2026-09-27 20:55:00
(5 days ago)
server hammer for exploited files
DDoS Attack
Brute-Force
Ping of Death
Hacking