๐บ๐ธ
TPI-Abuse
2025-08-16 19:30:21
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 16 15:30:14.602055 2025] [security2:error] [pid 28465:tid 28465] [client 2a0b:f4c2::11:41662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daos.org"] [uri "/wp-config.php.zip"] [unique_id "aKDcRpMFPAAeWKW1ylQQ3wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-16 02:48:10
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 15 22:48:05.662273 2025] [security2:error] [pid 15999:tid 15999] [client 2a0b:f4c2::11:18914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bonnesfrequences.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bonnesfrequences.com"] [uri "/frequences.sql"] [unique_id "aJ_xZY_f940eM7XDosU_twAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-01 20:03:29
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 01 16:03:20.612712 2025] [security2:error] [pid 2846163:tid 2846163] [client 2a0b:f4c2::11:62910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "viszin.com"] [uri "/wp-config.phped"] [unique_id "aDyyCKCNIiJ4ban_OR-6xgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-05-30 11:15:33
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ฉ๐ช
LRob
2025-05-30 11:00:21
(1 year ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
LRob
2025-05-30 10:45:16
(1 year ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
LRob
2025-05-20 10:15:12
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-05-19 00:20:23
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 18 20:20:16.275780 2025] [security2:error] [pid 3262978:tid 3263004] [client 2a0b:f4c2::11:23884] [client 2a0b:f4c2::11] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sweeneyzone.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sweeneyzone.com"] [uri "/adminer.sql"] [unique_id "aCp5QE1LSrbdbzZclDUg1QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-05-16 22:58:09
(1 year ago)
2025-05-16 20:30:01 /
2025-05-16 15:42:32 http://d3ivqzdymldr3c.cloudfront.net/
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-08 00:25:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 20:25:26.962736 2025] [security2:error] [pid 1404645:tid 1404645] [client 2a0b:f4c2::11:13102] [client 2a0b:f4c2::11] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nomorenicenice.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nomorenicenice.net"] [uri "/adminer.sql"] [unique_id "aBv59sLxoG3ezN8RfLwVMwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-07 03:58:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 23:58:49.960773 2025] [security2:error] [pid 389271:tid 389271] [client 2a0b:f4c2::11:11308] [client 2a0b:f4c2::11] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teleplussolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teleplussolutions.com"] [uri "/adminer.sql"] [unique_id "aBraeeBEHXyAWdTQb19LGAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 23:34:44
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 19:34:41.232496 2025] [security2:error] [pid 395414:tid 395414] [client 2a0b:f4c2::11:10182] [client 2a0b:f4c2::11] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gegkal.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gegkal.com"] [uri "/adminer.sql"] [unique_id "aBlLEXvuaxkN6zGVYKGjpQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 14:08:25
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 10:08:21.207717 2025] [security2:error] [pid 2457881:tid 2457881] [client 2a0b:f4c2::11:32358] [client 2a0b:f4c2::11] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||manosentuayuda.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "manosentuayuda.org"] [uri "/bd.sql"] [unique_id "aBjGVaxttju1klwPIo0MUAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 04:04:41
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 00:04:36.682962 2025] [security2:error] [pid 196971:tid 197015] [client 2a0b:f4c2::11:43168] [client 2a0b:f4c2::11] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alancphotography.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alancphotography.com"] [uri "/adminer.sql"] [unique_id "aBg41FMyW2OaH_1Pz_JNAwAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-04 07:54:07
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::11 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 03:54:00.763445 2025] [security2:error] [pid 1832122:tid 1832232] [client 2a0b:f4c2::11:23798] [client 2a0b:f4c2::11] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jeanpaullederer.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeanpaullederer.com"] [uri "/adminer.sql"] [unique_id "aBcdGJxOpVDRWMlL6TuyegAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack