🇺🇸
TPI-Abuse
2026-01-23 02:40:47
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 21:40:42.166570 2026] [security2:error] [pid 13628:tid 13628] [client 2001:41d0:305:2100::4e79:53660] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.baliaccommodationpadangpadang.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.baliaccommodationpadangpadang.com"] [uri "/[email protected] "] [unique_id "aXLfqmLfzYhe9Bh8A2AfKgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-10 16:33:19
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 11:33:07.581318 2026] [security2:error] [pid 24606:tid 24606] [client 2001:41d0:305:2100::4e79:59350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nccb.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nccb.org"] [uri "/theunion.com"] [unique_id "aWJ_Q9yvqI1WHccGj9kTZwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-10 13:34:16
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 08:34:11.172965 2026] [security2:error] [pid 25285:tid 25285] [client 2001:41d0:305:2100::4e79:41902] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brickyardinn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brickyardinn.com"] [uri "/mail to: [email protected] "] [unique_id "aWJVU84y_cJTk58ufzMNcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-08 16:42:41
(7 months ago)
(mod_security) mod_security (id:210381) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210381) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 08 11:42:37.609556 2026] [security2:error] [pid 395040:tid 395051] [client 2001:41d0:305:2100::4e79:37982] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianaconstructionaccidentlawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianaconstructionaccidentlawyer/%url%"] [unique_id "aV_efXXuaNHG638wwht2mgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-05 19:39:39
(7 months ago)
(mod_security) mod_security (id:240950) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:240950) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 14:39:31.880783 2026] [security2:error] [pid 1338321:tid 1338321] [client 2001:41d0:305:2100::4e79:47454] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/nav.php"] [unique_id "aVwTcziFRjfle8ymr4L4jAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-03 16:21:52
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 11:21:46.904848 2026] [security2:error] [pid 13502:tid 13502] [client 2001:41d0:305:2100::4e79:54350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.elcalamo.com|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.elcalamo.com"] [uri "/pda/ya\\xf1ez-derendimiento.PDB"] [unique_id "aVlCGnpubKUM0k6KjnrClQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-01-02 23:31:24
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 18:31:16.760138 2026] [security2:error] [pid 27865:tid 27865] [client 2001:41d0:305:2100::4e79:42726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bahamascruisersguide.com|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bahamascruisersguide.com"] [uri "/page26/snowbirdscompassrose.blogspot.com"] [unique_id "aVhVRA7S80rzUofILNqF4QAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-31 17:43:18
(7 months ago)
(mod_security) mod_security (id:240950) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:240950) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 12:43:11.502618 2025] [security2:error] [pid 16095:tid 16095] [client 2001:41d0:305:2100::4e79:53070] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.kentsmithfamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.kentsmithfamily.com"] [uri "/index.php"] [unique_id "aVVgrxVCkH_UlYqnVgPKtgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-31 04:39:01
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 23:38:54.193693 2025] [security2:error] [pid 6085:tid 6085] [client 2001:41d0:305:2100::4e79:48304] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||timberwolf-construction.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "timberwolf-construction.com"] [uri "/mail to: [email protected] "] [unique_id "aVSo3oxfhtgJWF0TFLOD7QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-17 20:35:28
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 17 15:35:22.523834 2025] [security2:error] [pid 22302:tid 22302] [client 2001:41d0:305:2100::4e79:57888] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.motioncontrolpartners.com|F|2"] [data ".egsi.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.motioncontrolpartners.com"] [uri "/http;/www.EGSi.com"] [unique_id "aUMUCp5Sp8OEApYR72sCKAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
MAGIC
2025-12-02 04:16:27
(8 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2025-11-12 03:23:39
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 22:23:32.387902 2025] [security2:error] [pid 22729:tid 22729] [client 2001:41d0:305:2100::4e79:33548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.efhgtc.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.efhgtc.org"] [uri "/[email protected] "] [unique_id "aRP9tNB-SiJ4OuRnu_ayggAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-17 18:54:57
(10 months ago)
(mod_security) mod_security (id:211180) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh. ...
show more
(mod_security) mod_security (id:211180) triggered by 2001:41d0:305:2100::4e79 (vps-8bd55d16.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 14:54:52.048674 2025] [security2:error] [pid 17052:tid 17052] [client 2001:41d0:305:2100::4e79:58974] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_HEADERS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "50"] [id "211180"] [rev "3"] [msg "COMODO WAF: Session Fixation: SessionID Parameter Name with No Referer||www.thecrimsonpirate.com|F|2"] [data "Matched Data: phpsessid found within REQUEST_HEADERS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thecrimsonpirate.com"] [uri "/forum/index.php"] [unique_id "aPKQ_K5VcXD7BNFVwGNeAAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Reinhard
2025-09-27 11:02:11
(11 months ago)
Unknown activity, but too many attacks with too many users.
Hacking
🇦🇺
advena
2025-09-26 11:15:59
(11 months ago)
2001:41d0:305:2100::4e79 (AS16276 OVH) was intercepted at 2025-09-26T11:09:58Z after violating WAF d ...
show more
2001:41d0:305:2100::4e79 (AS16276 OVH) was intercepted at 2025-09-26T11:09:58Z after violating WAF directive: 874a3e315c344b1281ad4f00046aab6f. Pre-cautionary/corrective action applied: managed_challenge.
show less
Web Spam
Hacking
Brute-Force
Web App Attack