๐บ๐ธ
TPI-Abuse
2026-03-15 16:30:15
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 12:30:09.689216 2026] [security2:error] [pid 8636:tid 8636] [client 98.159.226.67:62413] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jussetcotradinglimited.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jussetcotradinglimited.co"] [uri "/old/mysql.sql"] [unique_id "abbekeJ376AK3HZvfmK-pgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-15 11:41:10
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 15 07:41:03.793182 2026] [security2:error] [pid 22897:tid 23014] [client 98.159.226.67:39539] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||siestakeybch.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "siestakeybch.com"] [uri "/wallet.dat"] [unique_id "abaaz8beu4cMeH4IE_yzXQAAAoc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-03-14 23:33:41
(5 months ago)
/back/www.tar
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-03-14 23:29:03
(5 months ago)
Cloudflare WAF: Request Path: /restore/sftp-config.json Request Query: Host: foro.elhacker.net user ...
show more
Cloudflare WAF: Request Path: /restore/sftp-config.json Request Query: Host: foro.elhacker.net userAgent: Action: block Source: firewallManaged ASN Description: UK2NET-AS Country: NL Method: HEAD Timestamp: 2026-03-14T23:29:03Z ruleId: c2a2f414a67c409f90cccb6c5bba0215. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-03-14 23:21:40
(5 months ago)
Web app vulnerability scanning detected. Evidence: 98.159.226.67 - - [14/Mar/2026:23:21:38 +0000] "G ...
show more
Web app vulnerability scanning detected. Evidence: 98.159.226.67 - - [14/Mar/2026:23:21:38 +0000] "GET /restore/bak.zip HTTP/1.1" 404 44794 "-" "-"
98.159.226.67 - - [14/Mar/2026:23:21:39 +0000] "HEAD /old/backup.sql HTTP/1.1" 404 4147 "-" "-"
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-03-13 17:17:07
(5 months ago)
Suspicious HTTP(s) activity without a user agent provided
Bad Web Bot
๐ฌ๐ง
Axel
2026-03-12 18:50:29
(5 months ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /sftp-config. ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /sftp-config.json Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ฌ๐ง
pinguin
2026-03-04 12:35:16
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /old/sql.sql
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
Penny Packer
2026-03-04 05:45:07
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-28 20:11:59
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 28 15:11:51.338738 2026] [security2:error] [pid 17747:tid 17747] [client 98.159.226.67:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kryptonome.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kryptonome.com"] [uri "/backups/wallet.dat"] [unique_id "aaNMB6lK5I5ZGA6OL5d0BQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-02-28 08:32:19
(5 months ago)
[28/Feb/2026:09:32:15 +0100] 177226753594.383091 98.159.226.67 32183 217.154.7.177 80
[28/Feb/2026:0 ...
show more
[28/Feb/2026:09:32:15 +0100] 177226753594.383091 98.159.226.67 32183 217.154.7.177 80
[28/Feb/2026:09:32:16 +0100] 177226753635.748323 98.159.226.67 65063 217.154.7.177 80
[28/Feb/2026:09:32:18 +0100] 177226753875.472084 98.159.226.67 24263 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 14:57:24
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 09:57:21.566621 2026] [security2:error] [pid 31084:tid 31084] [client 98.159.226.67:30753] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capitalinvestingguides.com"] [uri "/backups/sftp-config.json"] [unique_id "aZXTUdJ7bA-WMrcbwndbagAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-16 10:07:23
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 98.159.226.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 16 05:07:18.725811 2026] [security2:error] [pid 3552001:tid 3552001] [client 98.159.226.67:62437] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robcohn.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robcohn.com"] [uri "/bak/dump.sql"] [unique_id "aZLsVm4D5sbj2rk_zjVCxAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-02-16 08:03:42
(6 months ago)
HTTP vulnerability scanning
Web App Attack
๐ซ๐ท
mikekarl
2026-02-16 05:15:04
(6 months ago)
Empty or bad user-agent.
Bad Web Bot