๐บ๐ธ
TPI-Abuse
2026-03-15 20:01:24
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 16:01:16.011602 2026] [security2:error] [pid 23099:tid 23099] [client 89.38.224.166:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kryptonome.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kryptonome.com"] [uri "/backup/dump.sql"] [unique_id "abcQDCP64WWSvK-zFJaqtAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-03-15 19:51:51
(4 months ago)
Triggered Cloudflare WAF (firewallManaged) from RS.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from RS.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /restore/website.gz
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ช๐ธ
librebit
2026-03-15 00:45:51
(4 months ago)
Brute force
Brute-Force
๐บ๐ธ
interbiznw.com
2026-03-15 00:12:02
(4 months ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
mikekarl
2026-03-14 21:13:47
(4 months ago)
Empty or bad user-agent.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-13 22:34:24
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 18:34:16.304396 2026] [security2:error] [pid 30720:tid 30720] [client 89.38.224.166:36093] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||headcount.dev|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "headcount.dev"] [uri "/mysql.sql"] [unique_id "abSQ6BBna2W8_KYT30oMqwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-03-13 22:27:40
(4 months ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-03-12 10:41:41
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 06:41:37.429804 2026] [security2:error] [pid 28870:tid 28870] [client 89.38.224.166:27039] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||usbea.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "usbea.com"] [uri "/usbea.com.sql"] [unique_id "abKYYQcdUR5n0rA6lD1XSQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-08 21:19:45
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 08 17:19:40.593195 2026] [security2:error] [pid 8207:tid 8207] [client 89.38.224.166:27585] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uppermotradingco.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uppermotradingco.com"] [uri "/back/wallet.dat"] [unique_id "aa3n7CAhnIN5cUomTMI_AwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 16:41:04
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 11:41:00.792690 2026] [security2:error] [pid 18701:tid 18706] [client 89.38.224.166:41117] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dpscsde.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dpscsde.com"] [uri "/sql.sql"] [unique_id "aaManJfAB3qDy_qXqO8RhgAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 06:39:21
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 89.38.224.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 01:39:17.184448 2026] [security2:error] [pid 17863:tid 17863] [client 89.38.224.166:22737] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.enriquelaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.enriquelaw.com"] [uri "/bak/www.sql"] [unique_id "aaKNlREC4J2fgFsFfBhKfAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-02-27 23:04:38
(4 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Penny Packer
2026-02-25 23:01:21
(4 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฎ๐น
madaello
2026-02-25 22:36:11
(4 months ago)
89.38.224.166 - - [25/Feb/2026:23:36:06 +0100] "HEAD /back/directory.tar HTTP/1.1" 404 2899 "-" "-"
...
show more
89.38.224.166 - - [25/Feb/2026:23:36:06 +0100] "HEAD /back/directory.tar HTTP/1.1" 404 2899 "-" "-"
89.38.224.166 - - [25/Feb/2026:23:36:07 +0100] "HEAD /back/sql.sql HTTP/1.1" 404 2898 "-" "-"
89.38.224.166 - - [25/Feb/2026:23:36:08 +0100] "HEAD /bak/directory.zip HTTP/1.1" 404 2899 "-" "-"
89.38.224.166 - - [25/Feb/2026:23:36:09 +0100] "HEAD /restore/config.json HTTP/1.1" 404 2897 "-" "-"
89.38.224.166 - - [25/Feb/2026:23:36:10 +0100] "HEAD /backups/dump.sql HTTP/1.1" 404 2898 "-" "-"
...
show less
Port Scan
๐ฌ๐ง
pinguin
2026-02-15 19:56:55
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from RS.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from RS.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /backup/public_html.zip
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot