πΊπΈ
TPI-Abuse
2026-03-15 16:30:17
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 12:30:08.907460 2026] [security2:error] [pid 2522:tid 2522] [client 98.159.226.66:61173] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jussetcotradinglimited.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jussetcotradinglimited.co"] [uri "/backup/dump.sql"] [unique_id "abbekOmyKwPTbXhwrzq7uQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 23:46:34
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 19:46:29.732888 2026] [security2:error] [pid 15814:tid 15814] [client 98.159.226.66:58647] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casinoaffiliateprogramsonline.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casinoaffiliateprogramsonline.com"] [uri "/back/wallet.dat"] [unique_id "abXzVcYeT_cUzOORlBP7rAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
Valhalla
2026-03-14 23:34:01
(5 months ago)
/backup/latest.zip
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-14 19:24:50
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 15:24:42.440416 2026] [security2:error] [pid 17745:tid 17745] [client 98.159.226.66:23709] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lundtrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lundtrading.com"] [uri "/backup/www.sql"] [unique_id "abW1-rjTFnvBXNUDm6Zh8AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Axel
2026-03-12 18:50:29
(5 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /sftp-config. ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /sftp-config.json Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
π¬π§
consul.to
2026-03-12 18:43:07
(5 months ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-11 16:50:38
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 12:50:29.716544 2026] [security2:error] [pid 31466:tid 31609] [client 98.159.226.66:22045] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bluetigertees.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bluetigertees.com"] [uri "/bak/sql.sql"] [unique_id "abGdVaqoLa1ei6au_XzO7wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Axel
2026-03-09 11:29:34
(5 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /backup/sftp- ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /backup/sftp-config.json Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
π¬π§
pinguin
2026-03-04 12:35:15
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method) ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/2 (HEAD method)
Endpoint: /backup/www.zip
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
πΊπΈ
Penny Packer
2026-03-04 05:44:56
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
πΊπΈ
COMPLEX
2026-03-02 01:45:19
(5 months ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
ASN: undefined (u ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: MANAGED_CHALLENGE
ASN: undefined (undefined)
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Empty string
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-02-28 20:16:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 15:16:20.534726 2026] [security2:error] [pid 10233:tid 10233] [client 98.159.226.66:26965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capitalinvestingguides.com"] [uri "/backup/sftp-config.json"] [unique_id "aaNNFH8QAOSogA76yMT-IwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
itsolon
2026-02-28 08:32:20
(5 months ago)
[28/Feb/2026:09:32:17 +0100] 177226753763.159575 98.159.226.66 39393 217.154.7.177 80
[28/Feb/2026:0 ...
show more
[28/Feb/2026:09:32:17 +0100] 177226753763.159575 98.159.226.66 39393 217.154.7.177 80
[28/Feb/2026:09:32:18 +0100] 177226753815.361076 98.159.226.66 60969 217.154.7.177 80
[28/Feb/2026:09:32:19 +0100] 177226753937.144738 98.159.226.66 65449 217.154.7.177 80
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-27 16:21:08
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 11:21:02.065757 2026] [security2:error] [pid 11661:tid 11661] [client 98.159.226.66:23389] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intercotrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intercotrading.com"] [uri "/backup/dump.sql"] [unique_id "aaHEbn_4_OzTwSdrSjDoTgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-02-24 20:27:18
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 15:27:11.039690 2026] [security2:error] [pid 28584:tid 28584] [client 98.159.226.66:35773] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||powderriverinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "powderriverinc.com"] [uri "/old/mysql.sql"] [unique_id "aZ4Jn3_8AdWYU7OiTUKf-gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack