🇺🇸
TPI-Abuse
2026-04-03 22:01:56
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 18:01:50.276831 2026] [security2:error] [pid 12773:tid 12773] [client 2602:fa5d::559:43548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archief.org"] [uri "/bak.htaccess"] [unique_id "adA4zj_lR4ZJOSto6Q3OpwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-31 08:21:28
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 04:21:19.483759 2026] [security2:error] [pid 5293:tid 5293] [client 2602:fa5d::559:46952] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||ipostsocialmedia.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ipostsocialmedia.com"] [uri "/[email protected] "] [unique_id "acuD_zSxFJfVffufFxqTPQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-24 09:36:02
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 05:35:52.620903 2026] [security2:error] [pid 5084:tid 5084] [client 2602:fa5d::559:58990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barkoskieelectric.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barkoskieelectric.com"] [uri "/mailto:[email protected] "] [unique_id "acJa-Hedro16MlddmWUGaQAAAAY"], referer: https://barkoskieelectric.com/email.htm
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-22 00:49:07
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 20:49:00.584510 2026] [security2:error] [pid 7972:tid 7972] [client 2602:fa5d::559:33312] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||keystroke.info|F|2"] [data ".php.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "keystroke.info"] [uri "/LocalSettings.php.backup"] [unique_id "ab88fOoevrvhoWH6s7dqMQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Nicolmn
2026-03-19 01:24:49
(5 months ago)
Web form spam ( id ltzmv-mm.l )
Web Spam
🇺🇸
TPI-Abuse
2026-03-18 04:33:59
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 18 00:33:52.272791 2026] [security2:error] [pid 21417:tid 21417] [client 2602:fa5d::559:51812] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.artigelisim.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.artigelisim.com"] [uri "/mailto:[email protected] "] [unique_id "aborMPp3lb_A4b4O1bNTwwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Nicolmn
2026-03-17 18:45:32
(5 months ago)
Web form spam ( id mmltz.l )
Web Spam
🇫🇷
Nicolmn
2026-03-14 19:10:59
(5 months ago)
Web form spam ( id prspctv.l )
Web Spam
🇫🇷
Nicolmn
2026-03-09 15:25:47
(5 months ago)
Web form spam ( id gf.l )
Web Spam
🇫🇷
Nicolmn
2026-03-03 17:30:57
(5 months ago)
Web form spam ( id crystl-plc.b )
Web Spam
🇺🇸
TPI-Abuse
2026-03-03 06:56:10
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 01:56:02.982485 2026] [security2:error] [pid 22017:tid 22017] [client 2602:fa5d::559:39696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||caretakerspestcontrol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caretakerspestcontrol.com"] [uri "/JMRussell.com"] [unique_id "aaaGAsDKQsZ0pVPn8RsI-QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Nicolmn
2026-03-02 00:40:17
(5 months ago)
Web form spam ( id mmcs.l )
Web Spam
🇺🇸
TPI-Abuse
2026-02-27 14:50:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 27 09:50:10.141883 2026] [security2:error] [pid 11750:tid 11750] [client 2602:fa5d::559:54112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lionheartpublications.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lionheartpublications.com"] [uri "/[email protected] "] [unique_id "aaGvIqrkn2BKOjTIQAfcEAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-02-26 21:05:01
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::559 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 16:04:54.359132 2026] [security2:error] [pid 27190:tid 27190] [client 2602:fa5d::559:53090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rodrandolph.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rodrandolph.com"] [uri "/facebook.com"] [unique_id "aaC1djvgxEwFQDelBHFqQgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Nicolmn
2026-02-25 17:34:02
(6 months ago)
Web form spam ( id lxmmcncpt.l )
Web Spam