๐บ๐ธ
TPI-Abuse
2025-02-21 16:55:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 11:55:03.724540 2025] [security2:error] [pid 13106:tid 13106] [client 2a0b:f4c2:1::1:47033] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||495metro.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "495metro.com"] [uri "/installer-data.sql"] [unique_id "Z7iv5wa2baccugiFB4NRugAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-21 08:14:11
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 03:14:07.134835 2025] [security2:error] [pid 8587:tid 8587] [client 2a0b:f4c2:1::1:5531] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dalessalesandservice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dalessalesandservice.com"] [uri "/mysql.sql"] [unique_id "Z7g1z5V3JwkQmmHQZOPIeAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-20 15:06:22
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 10:06:15.077646 2025] [security2:error] [pid 29590:tid 29590] [client 2a0b:f4c2:1::1:16659] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||36sovereignchambers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "36sovereignchambers.com"] [uri "/mysql.sql"] [unique_id "Z7dE5_IuslyaKMbjXphcsgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-20 11:19:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 06:19:34.716760 2025] [security2:error] [pid 13177:tid 13177] [client 2a0b:f4c2:1::1:56847] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anouk.ee|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anouk.ee"] [uri "/mysql.sql"] [unique_id "Z7cPxhtvPP2sSPUlHGZlywAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-19 11:53:05
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 19 06:52:58.391207 2025] [security2:error] [pid 17311:tid 17343] [client 2a0b:f4c2:1::1:15815] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||princesscastlebunkbed.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "princesscastlebunkbed.com"] [uri "/uploads/database.sql"] [unique_id "Z7XGGi-XD69bqYOyGyFupwAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-18 19:49:27
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 18 14:49:19.772929 2025] [security2:error] [pid 29663:tid 29681] [client 2a0b:f4c2:1::1:31125] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vivierae.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vivierae.com"] [uri "/wp-config.backup"] [unique_id "Z7TkP27xKBGmXI4p9HI2eQAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-18 04:02:46
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 17 23:02:41.802539 2025] [security2:error] [pid 15000:tid 15000] [client 2a0b:f4c2:1::1:8767] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||simplehandymanllc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "simplehandymanllc.com"] [uri "/installer-data.sql"] [unique_id "Z7QGYUXoST6g0Fm6DVLaHQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-10 20:50:55
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 10 15:50:43.630639 2025] [security2:error] [pid 26947:tid 26947] [client 2a0b:f4c2:1::1:18487] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "parastesh.org"] [uri "/downl.php"] [unique_id "Z6pmozzUPE421iJWMwiwhgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-10 19:27:17
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 10 14:27:13.054209 2025] [security2:error] [pid 23931:tid 23945] [client 2a0b:f4c2:1::1:51617] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nabsci.com"] [uri "/downl.php"] [unique_id "Z6pTEXj-U_r1z0YYG4gprAAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-09 21:13:27
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 09 16:13:22.418207 2025] [security2:error] [pid 2328984:tid 2328984] [client 2a0b:f4c2:1::1:30115] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shhcenter.com"] [uri "/wp-config.phptmp"] [unique_id "Z6kacucJ3ofu71Mdo5UeRwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-09 15:12:00
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 09 10:11:54.428012 2025] [security2:error] [pid 12723:tid 12723] [client 2a0b:f4c2:1::1:24781] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.louisvillecustomkitchens.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.louisvillecustomkitchens.com"] [uri "/db.sql"] [unique_id "Z6jFuj86jHACE_Gp8fln8gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-28 10:16:20
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 28 05:16:12.924340 2025] [security2:error] [pid 14993:tid 14993] [client 2a0b:f4c2:1::1:63445] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.atlantaliveworship.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.atlantaliveworship.com"] [uri "/db.sql"] [unique_id "Z5iubEVX_hkFCH2fKnFHJwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-24 23:46:16
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 24 18:46:04.843175 2025] [security2:error] [pid 32019:tid 32019] [client 2a0b:f4c2:1::1:27913] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.graymatterofdc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.graymatterofdc.com"] [uri "/db.sql"] [unique_id "Z5QmPEa5l_CZb9p1WGowugAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-19 05:50:00
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 sec ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:1::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 19 00:49:53.365736 2025] [security2:error] [pid 28445:tid 28445] [client 2a0b:f4c2:1::1:18465] [client 2a0b:f4c2:1::1] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neconebooks.com"] [uri "/wp-config.php.maj"] [unique_id "Z4ySgUnE8_y1QOc8X77SbAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-01-17 01:30:58
(1 year ago)
2025-01-16 07:27:32 http://d3sspl5ropfzm8.cloudfront.net/
2025-01-16 07:25:28 /
2025-01-16 02:27:42 ...
show more
2025-01-16 07:27:32 http://d3sspl5ropfzm8.cloudfront.net/
2025-01-16 07:25:28 /
2025-01-16 02:27:42 http://d3sspl5ropfzm8.cloudfront.net/
2025-01-16 06:54:57 /
2025-01-16 02:25:30 http://d3sspl5ropfzm8.cloudfront.net/
2025-01-16 07:25:26 /favicon.ico
show less
Web App Attack