πΊπΈ
TPI-Abuse
2026-07-29 21:09:34
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:09:25.947489 2026] [security2:error] [pid 365240:tid 365240] [client 67.21.33.215:56491] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||graymatterofdc.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "graymatterofdc.com"] [uri "/CookieAuth.dll"] [unique_id "ampsBbXT5Bwd5w0cjiN7gAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 20:40:15
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:40:07.503943 2026] [security2:error] [pid 237064:tid 237064] [client 67.21.33.215:50165] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clossglobal.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clossglobal.com"] [uri "/CookieAuth.dll"] [unique_id "amplJ7YN837HE2BfO-z-ngAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 19:53:09
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 15:53:01.205954 2026] [security2:error] [pid 18158:tid 18158] [client 67.21.33.215:51791] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wavecomputers.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wavecomputers.com"] [uri "/CookieAuth.dll"] [unique_id "ampaHR7Bc0rfVby48i_dvwAAAAQ"], referer: http://wavecomputers.com/CookieAuth.dll?GetLogon?formdir=1
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-07-29 19:41:48
(18 hours ago)
20 requests with url.path *.dll
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-29 19:01:23
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 15:01:16.353215 2026] [security2:error] [pid 13207:tid 13207] [client 67.21.33.215:54620] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||weirdlovemakers.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "weirdlovemakers.com"] [uri "/CookieAuth.dll"] [unique_id "ampN_Ht4WLu-dB0ySDnWggAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 17:45:05
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 13:44:58.022809 2026] [security2:error] [pid 451651:tid 451651] [client 67.21.33.215:52167] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stbms.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stbms.com"] [uri "/CookieAuth.dll"] [unique_id "amo8GqqDmXSnGyvKq4gC4AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 09:27:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 05:27:01.628639 2026] [security2:error] [pid 3427023:tid 3427065] [client 67.21.33.215:50086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tierrasolymar.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tierrasolymar.com"] [uri "/CookieAuth.dll"] [unique_id "amnHZd6GSbIplsOqQrWfBwAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 03:06:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 23:06:48.841808 2026] [security2:error] [pid 29996:tid 30009] [client 67.21.33.215:51388] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cargomarexpress.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cargomarexpress.com"] [uri "/CookieAuth.dll"] [unique_id "amluSNq5OVGXmLfFDaMx4wAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-07-29 03:06:16
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 02:47:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 22:47:56.542988 2026] [security2:error] [pid 89649:tid 89649] [client 67.21.33.215:60195] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockymtnfire.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockymtnfire.com"] [uri "/CookieAuth.dll"] [unique_id "amlp3KxoT0ujaehPgafyDAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 01:59:50
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 21:59:41.650441 2026] [security2:error] [pid 2806203:tid 2806203] [client 67.21.33.215:53725] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||easternimport.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "easternimport.com"] [uri "/CookieAuth.dll"] [unique_id "amlejV82osFIoiFWoukfOgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Axel
2026-07-28 12:22:02
(2 days ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||iii.vg|F|2 Phase: 2 Severity: CRITICAL URI: /CookieAuth.dll Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
π«π·
IRISIO
2026-07-28 10:41:08
(2 days ago)
scans/SQL injection/spam posts : 18 queries
Web App Attack
SQL Injection
πΊπΈ
TPI-Abuse
2026-07-28 05:17:22
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 67.21.33.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:17:15.957990 2026] [security2:error] [pid 2532843:tid 2532843] [client 67.21.33.215:59826] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backstore.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backstore.com"] [uri "/CookieAuth.dll"] [unique_id "amg7W2BGq6ukO_oHEbuoDAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 04:40:00
(2 days ago)
Web App Attack