TPI-Abuse
2025-06-10 07:06:21
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 10 03:06:14.547807 2025] [security2:error] [pid 1574098:tid 1574098] [client 2a0b:f4c2:2::40:39453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zacharypowers.com"] [uri "/wp-config.php.backup"] [unique_id "aEfZZuA2sUYkPQxZGrgOhwAAAAs"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-28 09:08:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 28 05:08:38.398972 2025] [security2:error] [pid 1393034:tid 1393034] [client 2a0b:f4c2:2::40:18561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rblep.com"] [uri "/wp-config.phppublic"] [unique_id "aDbSlr53AIsm3to_dwfwRAAAAAA"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-06 13:38:27
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 09:38:19.697320 2025] [security2:error] [pid 2327882:tid 2327882] [client 2a0b:f4c2:2::40:10433] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||virtualmediamasters.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "virtualmediamasters.net"] [uri "/migration.sql"] [unique_id "aBoQy0OnNY1-aJWQtBHa1AAAAAE"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-05 17:09:40
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 13:09:33.637442 2025] [security2:error] [pid 1229314:tid 1229314] [client 2a0b:f4c2:2::40:42481] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||havenlaneministries.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "havenlaneministries.com"] [uri "/adminer.sql"] [unique_id "aBjwzdQu4_w7jDfJwGGogQAAAAQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-05-05 05:05:59
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 01:05:53.637703 2025] [security2:error] [pid 53901:tid 53901] [client 2a0b:f4c2:2::40:22105] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paramountcapital.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paramountcapital.net"] [uri "/adminer.sql"] [unique_id "aBhHMVV6ub9MFdmebIwDJAAAAAA"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-23 02:59:55
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 22 22:59:48.818582 2025] [security2:error] [pid 15797:tid 15797] [client 2a0b:f4c2:2::40:44985] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||superzilla.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "superzilla.com"] [uri "/administrator/backups/database.sql"] [unique_id "aAhXpCmjhzyZAFuoo40qlwAAAAU"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-11 01:45:34
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 10 21:45:29.041711 2025] [security2:error] [pid 4323:tid 4323] [client 2a0b:f4c2:2::40:34303] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||encuentraunbuenabogado.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "encuentraunbuenabogado.com"] [uri "/wp-content/db.sql"] [unique_id "Z_h0ObkpiFd8eVBkj1ABBwAAAAQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-09 22:28:48
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 09 18:28:42.924531 2025] [security2:error] [pid 10555:tid 10555] [client 2a0b:f4c2:2::40:53515] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mixmediallc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mixmediallc.com"] [uri "/db.sql"] [unique_id "Z_b0mstu-rAtf3WbRgyZnwAAAAg"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-08 07:52:44
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 08 03:52:40.283527 2025] [security2:error] [pid 1210276:tid 1210276] [client 2a0b:f4c2:2::40:31769] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nationalenq.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nationalenq.com"] [uri "/wp-content/db.sql"] [unique_id "Z_TVyHD5OpxhWu74Yw3f3wAAABE"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-05 23:07:39
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 05 19:07:31.451316 2025] [security2:error] [pid 3160:tid 3160] [client 2a0b:f4c2:2::40:63545] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desertvacationvillas.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desertvacationvillas.com"] [uri "/wp-content/db.sql"] [unique_id "Z_G3s0nfn2yd7-kudsvghQAAAAE"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-05 07:53:30
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 05 03:53:23.020340 2025] [security2:error] [pid 15734:tid 15734] [client 2a0b:f4c2:2::40:6101] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||kenometer.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kenometer.com"] [uri "/db.sql"] [unique_id "Z_Dhc02JsyWVOlqjaf9DBwAAAAA"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-04-04 18:09:58
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 04 14:09:55.155220 2025] [security2:error] [pid 18552:tid 18552] [client 2a0b:f4c2:2::40:54671] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.calogerolawfirm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.calogerolawfirm.com"] [uri "/db.sql"] [unique_id "Z_Agc2NafU4YuOxW6hl3ngAAAAM"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-27 13:42:51
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 27 09:42:45.263331 2025] [security2:error] [pid 10413:tid 10413] [client 2a0b:f4c2:2::40:2861] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||meliaethelwoodard.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "meliaethelwoodard.com"] [uri "/database.sql"] [unique_id "Z-VV1SOj227OiPG08QXLzQAAAAQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-26 07:32:54
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 03:32:47.511043 2025] [security2:error] [pid 1696734:tid 1696734] [client 2a0b:f4c2:2::40:57119] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||godcanuseyou.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "godcanuseyou.com"] [uri "/database.sql"] [unique_id "Z-Otn1BblGjp2-wAtesk0QAAAAI"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-25 03:11:36
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): ... show more (mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::40 (tor-exit-40.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 23:11:31.479620 2025] [security2:error] [pid 19891:tid 19987] [client 2a0b:f4c2:2::40:21133] [client 2a0b:f4c2:2::40] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||minutosrobados.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "minutosrobados.com"] [uri "/database.sql"] [unique_id "Z-Ie47eM7om5-l0Jy2Lg0QAAAE0"] show less
Brute-Force
Bad Web Bot
Web App Attack