๐บ๐ธ
TPI-Abuse
2025-08-22 03:07:37
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 21 23:07:30.090451 2025] [security2:error] [pid 4859:tid 4859] [client 2602:f6f6:2:2634::1:39910] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||karenbernsteinlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "karenbernsteinlaw.com"] [uri "/ernsteinlaw.sql"] [unique_id "aKfe8rw5Tb6Hv5AI1IIyWgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-14 07:22:45
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 14 03:22:37.550637 2025] [security2:error] [pid 13920:tid 13920] [client 2602:f6f6:2:2634::1:48156] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zezel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zezel.com"] [uri "/el.sql"] [unique_id "aJ2OvXy3LBC5zMNBisxSpgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 11:02:03
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 27 07:01:55.826487 2025] [security2:error] [pid 6527:tid 6527] [client 2602:f6f6:2:2634::1:37972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.infojeffreysbay.com"] [uri "/.git/config"] [unique_id "aIYHI0B9F8EZicslpWZUUgAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-23 14:30:59
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 23 10:30:52.093414 2025] [security2:error] [pid 19143:tid 19143] [client 2602:f6f6:2:2634::1:38776] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.gjbenches.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.gjbenches.com"] [uri "/db1.sql"] [unique_id "aIDyHJrTaTIK-xNmzpUFmgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2025-07-18 08:05:02
(10 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-03 13:10:10
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 03 09:10:03.087071 2025] [security2:error] [pid 27144:tid 27144] [client 2602:f6f6:2:2634::1:34000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ronjamestelevision.com"] [uri "/wp-config.php.bak.a2"] [unique_id "aGaBK_NyIBMSNVXpjO5lZgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-13 00:59:24
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 12 20:59:20.207311 2025] [security2:error] [pid 3875660:tid 3875660] [client 2602:f6f6:2:2634::1:33050] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||twinls.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "twinls.com"] [uri "/adminer.sql"] [unique_id "aEt36KETpUDPRBvPeFNBdgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-02 12:07:36
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f6f6:2:2634::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 02 08:07:27.261062 2025] [security2:error] [pid 3490647:tid 3490647] [client 2602:f6f6:2:2634::1:44706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smilingorc.com"] [uri "/wp-config.php-bak"] [unique_id "aD2T_4kVBIL35iIEFMAPpQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack