🇦🇺
aranguren.org
2026-07-09 14:26:41
(1 month ago)
2602:fa5d::89 - - [10/Jul/2026:00:26:39 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Wind ...
show more
2602:fa5d::89 - - [10/Jul/2026:00:26:39 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.116 Safari/537.36"
2602:fa5d::89 - - [10/Jul/2026:00:26:39 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36"
2602:fa5d::89 - - [10/Jul/2026:00:26:39 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; MALNJS; rv:11.0) like Gecko"
2602:fa5d::89 - - [10/Jul/2026:00:26:40 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36"
2602:fa5d::89 - - [10/Jul/2026:00:26:40 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; MALNJS; rv:11.0) like Gecko"
2602:fa5d::89 - - [10/Jul/2026:00:26:40 +1000] "GET /ossec/ HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Windows N
...
show less
Bad Web Bot
🇩🇪
marcel-knorr.de
2026-07-07 05:41:34
(1 month ago)
[MK-Root1] Blocked by UFW
Brute-Force
Port Scan
🇫🇮
YF
2026-07-05 02:00:43
(1 month ago)
Suspicious contact page 403 errors
Web App Attack
🇺🇸
TPI-Abuse
2026-07-04 16:20:54
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 12:20:41.035488 2026] [security2:error] [pid 14112:tid 14112] [client 2602:fa5d::89:35570] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sellitwithsteve.listitwithsteve.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sellitwithsteve.listitwithsteve.com"] [uri "/mailto:[email protected] "] [unique_id "akky2SWixJS4OkX4c-j7rgAAAAo"], referer: https://www.sellitwithsteve.listitwithsteve.com/AboutKW.html
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
nixnut
2026-07-01 00:10:00
(2 months ago)
A bot tried to submit your contact form.
IP Address: 2602:fa5d::89
Browser: Mozilla/5.0 (Windows ...
show more
A bot tried to submit your contact form.
IP Address: 2602:fa5d::89
Browser: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
Bot Name/Realname: sjuohwtqyf
Bot Email Used: [email protected]
Trapped Field Value: zfrtuhqrdf
show less
Web Spam
Email Spam
🇺🇸
TPI-Abuse
2026-04-06 04:36:16
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 00:36:01.838900 2026] [security2:error] [pid 4498:tid 4498] [client 2602:fa5d::89:40974] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||techspertnet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "techspertnet.com"] [uri "/[email protected] "] [unique_id "adM4Ma-RUZHxBw3b_pQzVQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-06 00:26:17
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 20:25:59.524488 2026] [security2:error] [pid 21605:tid 21605] [client 2602:fa5d::89:51390] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||john-bell-associates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "john-bell-associates.com"] [uri "/reddit.com"] [unique_id "adL9l6-rWAWUrvGIDKEvUQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-28 22:36:05
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 18:35:57.168987 2026] [security2:error] [pid 2845:tid 2845] [client 2602:fa5d::89:50220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||69strains.com|F|2"] [data ".cannapages.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "69strains.com"] [uri "/www.cannapages.com"] [unique_id "achXzQVOMiAVZ7-M-H1SPwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-14 17:13:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 13:13:43.845169 2026] [security2:error] [pid 5744:tid 5744] [client 2602:fa5d::89:36322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brittb.com"] [uri "/bak.htaccess"] [unique_id "abWXRw4TxcIreMPhU5stBQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-12 15:42:16
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 11:42:09.519250 2026] [security2:error] [pid 14714:tid 14714] [client 2602:fa5d::89:41600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adoniahenterprises.com"] [uri "/goober_.htaccess"] [unique_id "abLe0fWUva_OGcXxLvpbBwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-03-11 21:09:38
(5 months ago)
(bad_user_agent) srv102 Bad User-Agent 2602:fa5d::89 (TR/Turkey/-): 10 in the last 3600 secs; Ports: ...
show more
(bad_user_agent) srv102 Bad User-Agent 2602:fa5d::89 (TR/Turkey/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-03-09 23:01:24
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa5d::89 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 19:01:14.093644 2026] [security2:error] [pid 8059:tid 8059] [client 2602:fa5d::89:55286] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||puduspoems.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puduspoems.com"] [uri "/web/20140107222105/http:/wwp.icq.com/scripts/WWPMsg.dll"] [unique_id "aa9ROgqPn1u3fX-UJZanzgAAABY"], referer: https://puduspoems.com/index.html
show less
Brute-Force
Bad Web Bot
Web App Attack