๐บ๐ธ
TPI-Abuse
2025-04-01 00:46:36
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 31 20:46:28.318731 2025] [security2:error] [pid 1770611:tid 1770611] [client 2001:67c:e28:1::4:35350] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffersonshaw.com"] [uri "/wp-config.php~~~"] [unique_id "Z-s3ZFFauzT5LwEV0kaaOgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-31 13:34:37
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 31 09:34:30.753529 2025] [security2:error] [pid 7157:tid 7157] [client 2001:67c:e28:1::4:60584] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||brazilianbottom.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brazilianbottom.com"] [uri "/db.sql"] [unique_id "Z-qZ5n8QX06tQIrrjLOy0wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-28 07:49:15
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 28 03:49:09.097516 2025] [security2:error] [pid 4890:tid 4890] [client 2001:67c:e28:1::4:33168] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||neconebooks.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "neconebooks.com"] [uri "/database.sql"] [unique_id "Z-ZUdb4kbJ_0Sak0Mr1nUQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 09:59:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 05:59:37.376881 2025] [security2:error] [pid 18613:tid 18681] [client 2001:67c:e28:1::4:46594] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cjherbalremedies.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cjherbalremedies.com"] [uri "/db.sql"] [unique_id "Z9fyiXVCuhCpiz50E_cDpAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-03-13 13:00:24
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-03 20:03:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 03 15:03:09.856572 2025] [security2:error] [pid 13257:tid 13273] [client 2001:67c:e28:1::4:51056] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vancekelly.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vancekelly.com"] [uri "/installer-data.sql"] [unique_id "Z8YK_R4Au0fEpSIm4ZtTcAAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-28 19:54:26
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 28 14:54:20.134899 2025] [security2:error] [pid 28601:tid 28601] [client 2001:67c:e28:1::4:45296] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||abeltours.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "abeltours.com"] [uri "/installer-data.sql"] [unique_id "Z8IUbHGqnFduOI5RMFUQPwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-28 14:52:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 28 09:51:59.377528 2025] [security2:error] [pid 7535:tid 7535] [client 2001:67c:e28:1::4:36456] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||circulodesonido.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circulodesonido.org"] [uri "/installer-data.sql"] [unique_id "Z8HNj4TcZJSb-JwqEcEGQwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-27 13:24:15
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 08:24:09.696537 2025] [security2:error] [pid 26804:tid 26804] [client 2001:67c:e28:1::4:45146] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||copanmaya.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "copanmaya.org"] [uri "/installer-data.sql"] [unique_id "Z8BneVRyG5Herika8Z98dQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-16 23:23:51
(1 year ago)
(mod_security) mod_security (id:210580) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210580) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 16 18:23:46.055969 2025] [security2:error] [pid 12544:tid 12544] [client 2001:67c:e28:1::4:55582] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "wp-config.php" at ARGS:file. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||usaangelinvestors.com|F|2"] [data "Matched Data: wp-config.php found within ARGS:file: wp-config.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "usaangelinvestors.com"] [uri "/download.php"] [unique_id "Z7JzgmzyCPQgyX9r-NdmLQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-10 20:47:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::4 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 10 15:47:45.833459 2025] [security2:error] [pid 18571:tid 18571] [client 2001:67c:e28:1::4:40270] [client 2001:67c:e28:1::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||local639.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "local639.com"] [uri "/installer-data.sql"] [unique_id "Z6pl8af8KozvFjt4-xa4YwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack