🇺🇸
TPI-Abuse
2025-11-19 21:13:45
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 16:13:38.359385 2025] [security2:error] [pid 21810:tid 21827] [client 2a06:1700:0:12::4:52998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kettlehill.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kettlehill.com"] [uri "/l.sql"] [unique_id "aR4zAot70MvcWILMkYztIAAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-18 10:22:07
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 05:22:01.061440 2025] [security2:error] [pid 450:tid 450] [client 2a06:1700:0:12::4:61938] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||misogynyis.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "misogynyis.com"] [uri "/misogynyis.sql"] [unique_id "aRxIyZ862YZtkyKRNjnPaQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-17 13:09:54
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 17 08:09:46.661555 2025] [security2:error] [pid 15421:tid 15516] [client 2a06:1700:0:12::4:36160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||captechinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "captechinc.com"] [uri "/.sql"] [unique_id "aRsemhhLA3oP6snqMCdFigAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
RtheCompany.eu
2025-11-12 09:19:00
(9 months ago)
Auto block
Hacking
SQL Injection
Brute-Force
🇺🇸
TPI-Abuse
2025-11-02 22:24:25
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 17:24:18.183151 2025] [security2:error] [pid 21886:tid 21886] [client 2a06:1700:0:12::4:58764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vintageamptubes.com"] [uri "/wp-config.php-n"] [unique_id "aQfaEsCqbXxOtdu7CvMIFQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-30 04:48:24
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 00:48:15.367436 2025] [security2:error] [pid 11396:tid 11396] [client 2a06:1700:0:12::4:52540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.studioarmanni.com"] [uri "/api/.env"] [unique_id "aQLuDyZJ5DgKDebPAe3JmgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-29 04:18:21
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 00:18:16.479914 2025] [security2:error] [pid 17181:tid 17181] [client 2a06:1700:0:12::4:26438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.psychiatryabuse.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.psychiatryabuse.com"] [uri "/atryabuse.sql"] [unique_id "aQGViFnObRfTrtU6J659YwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2025-10-26 06:22:37
(10 months ago)
(db_admin_scan) srv102 DB admin scan 2a06:1700:0:12::4 (Unknown): 1 in the last 3600 secs; Ports: *; ...
show more
(db_admin_scan) srv102 DB admin scan 2a06:1700:0:12::4 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-10-22 15:28:16
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 22 11:28:08.839395 2025] [security2:error] [pid 5629:tid 5629] [client 2a06:1700:0:12::4:40206] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||churchbehindthewalls.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "churchbehindthewalls.com"] [uri "/churchbehindthewall.sql"] [unique_id "aPj4CHE8fvuRL7rqYq2gEQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-21 18:11:02
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 21 14:10:56.089091 2025] [security2:error] [pid 2729:tid 2729] [client 2a06:1700:0:12::4:7072] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gegkal.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gegkal.com"] [uri "/ge.sql"] [unique_id "aPfMsKqAQJQ3T5lNBoFqSQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-18 11:47:28
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 18 07:47:22.439836 2025] [security2:error] [pid 4093:tid 4093] [client 2a06:1700:0:12::4:22438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||garantaconsulting.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "garantaconsulting.com"] [uri "/ing.sql"] [unique_id "aPN-SgDEuTwuOO6QQbyn9wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-13 20:08:01
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 13 16:07:54.179115 2025] [security2:error] [pid 3595:tid 3595] [client 2a06:1700:0:12::4:32210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deborahbein.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deborahbein.com"] [uri "/deb.sql"] [unique_id "aO1cGgy2yF42WUoXxM2wwgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-13 04:21:13
(10 months ago)
(mod_security) mod_security (id:210831) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210831) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 13 00:21:05.602699 2025] [security2:error] [pid 22224:tid 22224] [client 2a06:1700:0:12::4:58058] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.sigridsnaturalfoods.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.sigridsnaturalfoods.com"] [uri "/"] [unique_id "aOx-MVhTvWq2cb8a43oNMgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-11 07:47:14
(10 months ago)
(mod_security) mod_security (id:210831) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210831) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 03:47:06.697322 2025] [security2:error] [pid 1090:tid 1090] [client 2a06:1700:0:12::4:5068] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.fnavarro.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.fnavarro.com"] [uri "/"] [unique_id "aOoLekTC25sBIwbsKJpQ_QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-09 16:36:12
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a06:1700:0:12::4 (bucarest01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 12:36:05.201277 2025] [security2:error] [pid 12345:tid 12345] [client 2a06:1700:0:12::4:14140] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||circleofsound.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circleofsound.org"] [uri "/eofsound.sql"] [unique_id "aOfkdVhoyz7FUgG4JuESCQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack