๐จ๐ณ
ThreatBook.io
2025-05-05 23:04:50
(1 year ago)
2025-05-05 19:51:11 /
2025-05-05 19:51:10 /
2025-05-05 19:51:13 /
2025-05-05 19:51:15 /
2025-05-05 1 ...
show more
2025-05-05 19:51:11 /
2025-05-05 19:51:10 /
2025-05-05 19:51:13 /
2025-05-05 19:51:15 /
2025-05-05 19:51:14 /
2025-05-05 19:51:16 /
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 16:16:11
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 12:16:06.798775 2025] [security2:error] [pid 1191054:tid 1191054] [client 2a0b:f4c2::12:16672] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rebelhollowfarm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rebelhollowfarm.com"] [uri "/adminer.sql"] [unique_id "aBjkRlwch2zhBd3Xswl3xAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-04 15:48:26
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 11:48:22.254682 2025] [security2:error] [pid 3363570:tid 3363570] [client 2a0b:f4c2::12:8624] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||primacomm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "primacomm.com"] [uri "/wp-content/database.sql"] [unique_id "aBeMRmVqOOW1qxoaRi3AIQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-03 14:32:00
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 03 10:31:55.657500 2025] [security2:error] [pid 3124297:tid 3124297] [client 2a0b:f4c2::12:62624] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||weird.eco|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "weird.eco"] [uri "/administrator/backups/database.sql"] [unique_id "aBYo29dkJlpdpBYTPGrgtAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-27 03:29:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 26 23:29:37.931940 2025] [security2:error] [pid 16527:tid 16527] [client 2a0b:f4c2::12:28998] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||parastesh.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "parastesh.org"] [uri "/adminer.sql"] [unique_id "aA2kobjWRM4UoNmlhzqC3QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-25 01:47:50
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 24 21:47:44.618574 2025] [security2:error] [pid 1541:tid 1541] [client 2a0b:f4c2::12:51416] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hawaiivacations.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hawaiivacations.com"] [uri "/adminer.sql"] [unique_id "aArpwO2nIWBuEGHrrXeGYgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2025-04-23 09:16:35
(1 year ago)
Wordpress login attempts
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-04-18 21:04:13
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 17:04:07.678856 2025] [security2:error] [pid 13192:tid 13204] [client 2a0b:f4c2::12:30966] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||maryschalkdesign.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "maryschalkdesign.com"] [uri "/administrator/backups/database-sql.sql"] [unique_id "aAK-R3SFlvRKVigoREjsygAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-18 20:00:49
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 18 16:00:40.168678 2025] [security2:error] [pid 5434:tid 5434] [client 2a0b:f4c2::12:37602] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||meganmurph.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "meganmurph.com"] [uri "/administrator/backups/database-sql.sql"] [unique_id "aAKvaN0GePb7dAwpNWfdzwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-08 06:32:16
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 08 02:32:08.454504 2025] [security2:error] [pid 22191:tid 22191] [client 2a0b:f4c2::12:61922] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/uploads/dump.sql"] [unique_id "Z_TC6BrDRyuh89vFEaHvJQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-07 07:49:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 07 03:48:59.431128 2025] [security2:error] [pid 412709:tid 412709] [client 2a0b:f4c2::12:45442] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.oldworldfineantiques.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.oldworldfineantiques.com"] [uri "/database.sql"] [unique_id "Z_ODa36YxhciqvFSE3MIWwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-04 07:23:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 04 03:23:50.742654 2025] [security2:error] [pid 7917:tid 7963] [client 2a0b:f4c2::12:21660] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nepsco.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nepsco.com"] [uri "/db.sql"] [unique_id "Z--JBV_gfbM8WEu0fqqJ4AAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-03 18:34:47
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 03 14:34:39.511084 2025] [security2:error] [pid 16851:tid 16851] [client 2a0b:f4c2::12:12384] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||speedgo.mx|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "speedgo.mx"] [uri "/database.sql"] [unique_id "Z-7Uv6tJHEpyeijMlr0H1AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2025-04-03 03:49:54
(1 year ago)
[03/Apr/2025:04:49:48.017777 +0100] Z-4FXNSeGy_TnS4paEWxygAAABU 2a0b:f4c2::12 56522 188.246.206.60 7 ...
show more
[03/Apr/2025:04:49:48.017777 +0100] Z-4FXNSeGy_TnS4paEWxygAAABU 2a0b:f4c2::12 56522 188.246.206.60 7081
[03/Apr/2025:04:49:48.898674 +0100] Z-4FXB0ZjvBa63Gs-ebiWQAAAEU 2a0b:f4c2::12 56540 188.246.206.60 7081
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-04-02 22:54:37
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::12 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 02 18:54:32.247406 2025] [security2:error] [pid 17116:tid 17116] [client 2a0b:f4c2::12:32966] [client 2a0b:f4c2::12] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intrinsicdiscovery.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intrinsicdiscovery.com"] [uri "/db.sql"] [unique_id "Z-3AKJ5rSXmXfnj_ibjkKgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack