🇺🇸
TPI-Abuse
2025-02-28 03:14:46
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 27 22:14:36.157560 2025] [security2:error] [pid 32208:tid 32208] [client 2a0b:f4c2:2::55:35821] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||fletcherdouglas.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fletcherdouglas.com"] [uri "/installer-data.sql"] [unique_id "Z8EqHB7nQO47f-eYxp07AAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-02-26 03:56:35
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 25 22:56:31.919355 2025] [security2:error] [pid 29583:tid 29583] [client 2a0b:f4c2:2::55:57859] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clickablebonus.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clickablebonus.com"] [uri "/mysql.sql"] [unique_id "Z76Q79f8hzftBkV9SdhlSwAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-02-24 22:23:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 24 17:23:09.727372 2025] [security2:error] [pid 21000:tid 21000] [client 2a0b:f4c2:2::55:15035] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nearfieldchrist.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nearfieldchrist.com"] [uri "/wp-content/mysql.sql"] [unique_id "Z7zxTZNo4linHT6ztllOmwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-02-24 17:01:17
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 24 12:01:10.812580 2025] [security2:error] [pid 2004625:tid 2004625] [client 2a0b:f4c2:2::55:62253] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pluralmatrix.net"] [uri "/wp-config.php5"] [unique_id "Z7yl1kPh3UcwRL-WiNbNVgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-02-20 18:02:54
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 13:02:49.427253 2025] [security2:error] [pid 2500805:tid 2500805] [client 2a0b:f4c2:2::55:40943] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cayman-islands-real-estate.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cayman-islands-real-estate.com"] [uri "/mysql.sql"] [unique_id "Z7duSWEvqOqY4rFTctDWgQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-02-19 23:58:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 19 18:58:55.865981 2025] [security2:error] [pid 23757:tid 23757] [client 2a0b:f4c2:2::55:36797] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bosdkbook.com"] [uri "/download.php"] [unique_id "Z7ZwP3UstZjdQM52BiCEZAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-02-10 19:26:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 10 14:26:46.796190 2025] [security2:error] [pid 7674:tid 7674] [client 2a0b:f4c2:2::55:56541] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furryfriendzy.org"] [uri "/download.php"] [unique_id "Z6pS9umjU1RJV7N0U3B0OgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
exxos
2025-01-16 16:27:35
(1 year ago)
php-rapid-access attacks
DDoS Attack
🇺🇸
TPI-Abuse
2024-11-28 13:05:55
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 28 08:05:48.497423 2024] [security2:error] [pid 31411:tid 31411] [client 2a0b:f4c2:2::55:26023] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.importadorapazromero.com"] [uri "/.git/config"] [unique_id "Z0hqrDAZbxNOP4EACUly0wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-11-12 11:26:14
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 12 06:26:05.126150 2024] [security2:error] [pid 602412:tid 602412] [client 2a0b:f4c2:2::55:61397] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||quicksmogsandiego.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "quicksmogsandiego.com"] [uri "/backups.sql"] [unique_id "ZzM7TYTMbyY9gxu4_Rn3-AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-10-18 08:41:27
(1 year ago)
(mod_security) mod_security (id:210831) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210831) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 18 04:41:23.348128 2024] [security2:error] [pid 27284:tid 27284] [client 2a0b:f4c2:2::55:41253] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.myclassicvw.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.myclassicvw.com"] [uri "/"] [unique_id "ZxIfM8jgTWLetLv-rmORjQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-08-15 17:02:37
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 13:02:34.082258 2024] [security2:error] [pid 374:tid 374] [client 2a0b:f4c2:2::55:41389] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||starvationacres.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "starvationacres.us"] [uri "/starva.sql"] [unique_id "Zr40qvx0ah-XrNZWHXTPHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-08-10 01:43:37
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 21:43:31.834489 2024] [security2:error] [pid 595:tid 595] [client 2a0b:f4c2:2::55:6753] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.h20.quest"] [uri "/.git/config"] [unique_id "ZrbFw6adQjJK-UPYuaoMoAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-08-09 14:50:08
(2 years ago)
(mod_security) mod_security (id:234930) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:234930) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 10:50:03.568454 2024] [security2:error] [pid 26291:tid 26291] [client 2a0b:f4c2:2::55:53909] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6787"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||1954topresent.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "1954topresent.com"] [uri "/blog/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "ZrYsmxn0WmxElIc0ceawigAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-08-07 13:52:40
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2:2::55 (tor-exit-55.for-privacy.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 07 09:52:33.816368 2024] [security2:error] [pid 25937:tid 25937] [client 2a0b:f4c2:2::55:23611] [client 2a0b:f4c2:2::55] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||reyadecostarica.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "reyadecostarica.com"] [uri "/adecostarica.sql"] [unique_id "ZrN8IUcak6bkL_IggGNruAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack