๐บ๐ธ
TPI-Abuse
2026-06-10 00:16:51
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 20:16:44.552474 2026] [security2:error] [pid 3814:tid 3814] [client 2a03:e600:100::12:41154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.innatmichaellynns.com"] [uri "/.git/config"] [unique_id "aiis7Mf3gyhrN3MX2TIdtwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:19:12
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:19:03.778341 2026] [security2:error] [pid 28310:tid 28344] [client 2a03:e600:100::12:54018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.geekshop.com"] [uri "/.git/config"] [unique_id "aiewV6cUIIpaJdUCE6WSxwAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 19:11:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 15:11:50.597344 2026] [security2:error] [pid 30564:tid 30564] [client 2a03:e600:100::12:46286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.loveoflearning.com"] [uri "/.git/config"] [unique_id "aiXCdoVHZaR7rL2Ar9YZHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 05:19:01
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 01:18:54.673201 2026] [security2:error] [pid 24047:tid 24047] [client 2a03:e600:100::12:38958] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||christianconsulting.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "christianconsulting.net"] [uri "/dump.sql"] [unique_id "agAVPvpTVEmVnR7M2wE55wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 17:45:26
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 13:45:18.816727 2026] [security2:error] [pid 2350:tid 2350] [client 2a03:e600:100::12:43294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||cliniquecavalancia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cliniquecavalancia.com"] [uri "/cliniqu.sql"] [unique_id "af9yro1PqMs_E09ZX5fG-AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-05-09 04:37:17
(1 month ago)
[SatMay0906:37:12.1480042026][security2:error][pid3025858:tid3025986][client2a03:e600:100::12:0]ModS ...
show more
[SatMay0906:37:12.1480042026][security2:error][pid3025858:tid3025986][client2a03:e600:100::12:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"craniosacraltherapy.ch\"][uri\"/altherapy_com.sql\"][unique_id\"af65-AQuiS039kvXMfkKfwAAARE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 15:42:31
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 11:42:22.664975 2026] [security2:error] [pid 5032:tid 5032] [client 2a03:e600:100::12:59900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/t_com.sql"] [unique_id "ae-D3o-I33FBtwFpDbL6QgAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-26 21:03:55
(1 month ago)
2026-04-26 08:00:47,325 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:e600:100::12
2026-04- ...
show more
2026-04-26 08:00:47,325 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:e600:100::12
2026-04-26 12:01:37,806 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:e600:100::12
2026-04-26 18:01:35,451 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:e600:100::12
2026-04-26 21:01:32,940 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:e600:100::12
2026-04-27 00:03:53,822 fail2ban.actions [7718]: NOTICE [tor] Ban 2a03:e600:100::12
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-25 16:34:40
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 12:34:36.160815 2026] [security2:error] [pid 10878:tid 10878] [client 2a03:e600:100::12:54820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kh6jim.com"] [uri "/wp-config.php~~"] [unique_id "aeztHPshtr7fx85-lGnl2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 05:34:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 01:34:34.648173 2026] [security2:error] [pid 2666566:tid 2666566] [client 2a03:e600:100::12:42892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magacine.tv"] [uri "/wp-config.php.bak"] [unique_id "aemvaucXF85bgilPCCFaDAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-04-17 16:08:10
(1 month ago)
[FriApr1718:08:03.7663262026][security2:error][pid2695010:tid2695031][client2a03:e600:100::12:0]ModS ...
show more
[FriApr1718:08:03.7663262026][security2:error][pid2695010:tid2695031][client2a03:e600:100::12:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\^/wp-content/plugins/[\^/] /\(readme\\\\\\\\.txt\|changelog\\\\\\\\.txt\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"381\"][id\"960828\"][msg\"WordPresspluginenumerationblocked\"][hostname\"radiofantasy.net\"][uri\"/wp-content/plugins/clever-fox/readme.txt\"][unique_id\"aeJa47eeN9gnM9sluP6VzQAAAMI\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 02:34:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 22:34:07.750769 2026] [security2:error] [pid 3846538:tid 3846538] [client 2a03:e600:100::12:35966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.old" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rambleandprose.com"] [uri "/wp-config.old"] [unique_id "aeGcHz81KFTx8hFgConlgwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-04-15 10:44:00
(1 month ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-14 13:05:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 09:05:11.879076 2026] [security2:error] [pid 3668787:tid 3668787] [client 2a03:e600:100::12:55730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "admiralpointe.com"] [uri "/wp-config.php~~~"] [unique_id "ad47hxJHkftFEL1Umo2POQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-10 13:57:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appli ...
show more
(mod_security) mod_security (id:210492) triggered by 2a03:e600:100::12 (tor-exit-anonymizer-v6.appliedprivacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 09:57:12.846096 2026] [security2:error] [pid 2150838:tid 2150838] [client 2a03:e600:100::12:36254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allisonbtaylor.com"] [uri "/wp-config.phptmp"] [unique_id "adkBuGagNV7ey2svuk68dwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack