πΊπΈ
TPI-Abuse
2025-03-23 10:35:56
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 23 06:35:49.910794 2025] [security2:error] [pid 3742888:tid 3742888] [client 2a0b:f4c2:1::1:9979] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||christineaholtz.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "christineaholtz.com"] [uri "/wp-content/database.sql"] [unique_id "Z9_kBVRzXRN6RACPdtLAnQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-23 05:42:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 23 01:42:35.693412 2025] [security2:error] [pid 6102:tid 6102] [client 2a0b:f4c2:1::1:12729] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customhumanrobots.com"] [uri "/wp-config.php.old"] [unique_id "Z9-fS0KyQig2eRlAjT_sqAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2025-03-19 12:30:24
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
π©πͺ
on-com
2025-03-09 04:01:33
(1 year ago)
URL scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-05 14:13:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 05 09:13:49.683091 2025] [security2:error] [pid 2623261:tid 2623261] [client 2a0b:f4c2:1::1:50351] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||microkerneltechnologies.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "microkerneltechnologies.com"] [uri "/db.sql"] [unique_id "Z8hcHR8RNQftV8T8gFdlVgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-03 16:57:48
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 03 11:57:41.294019 2025] [security2:error] [pid 21659:tid 21659] [client 2a0b:f4c2:1::1:55717] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||modestosoftwater.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "modestosoftwater.com"] [uri "/installer-data.sql"] [unique_id "Z8XfhRyvNuc1Hwljr857ngAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-03 07:15:15
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 03 02:15:07.230867 2025] [security2:error] [pid 4083333:tid 4083333] [client 2a0b:f4c2:1::1:50019] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||savannah-house.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "savannah-house.com"] [uri "/installer-data.sql"] [unique_id "Z8VW-2ctr5Eid4LoQlCK1AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-01 03:11:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 28 22:11:28.997998 2025] [security2:error] [pid 13361:tid 13361] [client 2a0b:f4c2:1::1:20189] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fernfield.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fernfield.com"] [uri "/mysql.sql"] [unique_id "Z8J64DYNKHYzYQP0xDXglgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-02-26 08:55:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 26 03:55:26.378067 2025] [security2:error] [pid 31641:tid 31641] [client 2a0b:f4c2:1::1:52107] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||johnsolinski.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "johnsolinski.com"] [uri "/mysql.sql"] [unique_id "Z77W_hQD-n-qCmNGtUH_SwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-02-26 07:33:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 26 02:33:45.518157 2025] [security2:error] [pid 18838:tid 18838] [client 2a0b:f4c2:1::1:53471] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coolerboxes.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coolerboxes.com"] [uri "/wp-content/mysql.sql"] [unique_id "Z77D2TbNcd69lPLrw4AjJQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
XICTRON
2025-02-26 06:35:03
(1 year ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
πΊπΈ
TPI-Abuse
2025-02-25 23:56:03
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 25 18:55:58.384786 2025] [security2:error] [pid 2714:tid 2714] [client 2a0b:f4c2:1::1:19267] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swcbsa.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swcbsa.org"] [uri "/mysql.sql"] [unique_id "Z75YjpY3zk9AyeYe8LYYHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-02-22 08:35:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 22 03:35:12.058403 2025] [security2:error] [pid 915674:tid 915674] [client 2a0b:f4c2:1::1:13339] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.genesis-castle.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.genesis-castle.com"] [uri "/mysql.sql"] [unique_id "Z7mMQDbSmcMz348PPhbXogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-02-22 05:28:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 22 00:28:15.641143 2025] [security2:error] [pid 4031:tid 4031] [client 2a0b:f4c2:1::1:13697] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||estudiovarela.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "estudiovarela.com"] [uri "/mysql.sql"] [unique_id "Z7lgbxCVB7B5UTH4QAgXuAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-02-21 23:48:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 18:48:11.601549 2025] [security2:error] [pid 15130:tid 15130] [client 2a0b:f4c2:1::1:36031] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bikiniadvice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikiniadvice.com"] [uri "/mysql.sql"] [unique_id "Z7kQu4w6LoBygf5_JTx49AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack