🇺🇸
dtorrer
2026-09-08 23:04:10
(2 hours ago)
Client attempted to submit spam on a website post.
Blog Spam
🇺🇸
TPI-Abuse
2026-09-07 04:24:12
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:24:06.287502 2026] [security2:error] [pid 31716:tid 31716] [client 45.71.17.24:36523] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holgerfeld.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "ap48ZpQs3RcikrPbk6nA8AAAAAs"], referer: http://holgerfeld.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 13:53:43
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:53:34.950896 2026] [security2:error] [pid 20675:tid 20675] [client 45.71.17.24:31191] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lockdownclaim.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lockdownclaim.com"] [uri "/mailto:[email protected] "] [unique_id "apl73oT21SrOE3X30SbSLAAAABE"], referer: http://lockdownclaim.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
sefinek.net
2026-08-01 10:20:24
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (H ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (HEAD) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/96.0.4664.45 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-07-24 13:13:08
(1 month ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-09 03:14:10
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 23:14:03.822075 2026] [security2:error] [pid 1117:tid 1117] [client 45.71.17.24:55835] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "ak8R-5TWjEAbXJotD_m2LgAAAAI"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Steve
2026-06-30 19:04:03
(2 months ago)
Forum Spam
Web Spam
🇺🇸
TPI-Abuse
2026-04-16 21:30:24
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 17:30:17.080437 2026] [security2:error] [pid 4115181:tid 4115181] [client 45.71.17.24:44401] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalswisscorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "aeFU6SyaXTH-Nefn8z6psQAAAA0"], referer: http://capitalswisscorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
robotstxt
2026-04-06 13:48:07
(5 months ago)
45.71.17.24 - - [06/Apr/2026:13:47:23 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 11 ...
show more
45.71.17.24 - - [06/Apr/2026:13:47:23 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 11341 "https://e-learning.qualipharmagroup.com" rt="0.330" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="e-learning.qualipharmagroup.com" sn="e-learning.qualipharmagroup.com" ru="/mailto:[email protected] " u="/index.php" ucs="-" ua="unix:/var/run/php/elearning82.sock" us="404" uct="0.000" urt="0.330"
45.71.17.24 - - [06/Apr/2026:13:47:24 +0000] "GET /mailto:[email protected] HTTP/1.1" 404 11341 "https://e-learning.qualipharmagroup.com" rt="0.286" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" "-" h="e-learning.qualipharmagroup.com" sn="e-learning.qualipharmagroup.com" ru="/mailto:[email protected] " u="/index.php" ucs="-" ua="unix:/var/run/php/elearning82.sock" us="404" uct="0.000" urt="0.286"
45.71.17.24 - - [06/Apr/2026
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-03-23 01:03:54
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 21:03:45.901288 2026] [security2:error] [pid 11215:tid 11215] [client 45.71.17.24:44937] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||CapitalSwissCorp.com:80|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalswisscorp.com"] [uri "/mailto:[email protected] "] [unique_id "acCRceBRuGIIYH_gPQtuBQAAAA0"], referer: http://CapitalSwissCorp.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-22 21:21:29
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 45.71.17.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 17:21:26.351160 2026] [security2:error] [pid 4010:tid 4010] [client 45.71.17.24:51189] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||HOLGERFELD.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holgerfeld.com"] [uri "/mailto:[email protected] "] [unique_id "acBdVrUbA0AgZ6qzcqgPpQAAAAE"], referer: http://HOLGERFELD.com
show less
Brute-Force
Bad Web Bot
Web App Attack