๐บ๐ธ
TPI-Abuse
2025-09-04 14:58:50
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 04 10:58:45.577449 2025] [security2:error] [pid 10695:tid 10695] [client 2a0b:f4c2::16:54740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||enriquejezik.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "enriquejezik.com"] [uri "/ezik.sql"] [unique_id "aLmpJaX1tmbbfJjLyBtxCAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2025-09-03 01:59:28
(1 year ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-02 16:17:49
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 12:17:43.768038 2025] [security2:error] [pid 3783:tid 3783] [client 2a0b:f4c2::16:43926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.monogay.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.monogay.org"] [uri "/backup.sql"] [unique_id "aLcYp-cyZ77MePYAADgEngAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-01 18:42:40
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 01 14:42:35.661073 2025] [security2:error] [pid 27756:tid 27774] [client 2a0b:f4c2::16:46652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "culturallyyours.org"] [uri "/wp-config.php.zip"] [unique_id "aLXpG3IA3HS7BZIKSq9r-wAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-09-01 01:55:14
(1 year ago)
WP_MALWARE_PROBE
Hacking
Web App Attack
๐ซ๐ท
dynamix
2025-08-31 15:07:31
(1 year ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-26 18:11:51
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 26 14:11:43.751658 2025] [security2:error] [pid 1015:tid 1015] [client 2a0b:f4c2::16:27182] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||imbrasacademic.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "imbrasacademic.com"] [uri "/mic.sql"] [unique_id "aK3436K-i6Ikm0ekwxVCVAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-20 06:38:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 20 02:37:56.182992 2025] [security2:error] [pid 28839:tid 28839] [client 2a0b:f4c2::16:26498] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.psscififilmfest.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.psscififilmfest.org"] [uri "/bck.sql"] [unique_id "aKVtRCR4wJmfEbQU720kigAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-17 22:27:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 17 18:27:05.906847 2025] [security2:error] [pid 6838:tid 6838] [client 2a0b:f4c2::16:37806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bennoyes.com"] [uri "/wp-config.php.zip"] [unique_id "aKJXOeouQINjwplMOYkV-QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-08-14 03:00:48
(1 year ago)
(modsecurity) srv104 ModSecurity 2a0b:f4c2::16 (Unknown): 5 in the last 3600 secs; Ports: *; Directi ...
show more
(modsecurity) srv104 ModSecurity 2a0b:f4c2::16 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-13 05:01:00
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 13 01:00:54.281734 2025] [security2:error] [pid 626326:tid 626339] [client 2a0b:f4c2::16:33850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||property-management-companies-chicago.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "property-management-companies-chicago.com"] [uri "/2022-perty-management-companies-chicago.sql"] [unique_id "aJwcBgA5sNk6258hAyAEAAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2025-06-22 11:06:46
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: BLOCK
Protocol: HTTP/2 (GET method) ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-06-18 08:22:35
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 18 04:22:27.149622 2025] [security2:error] [pid 3670438:tid 3670438] [client 2a0b:f4c2::16:19612] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tonysargbooks.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tonysargbooks.com"] [uri "/sargbooks-2022.sql"] [unique_id "aFJ3Q_Fquo8t8mb0SL9D8AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-25 22:38:49
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 25 18:38:41.940330 2025] [security2:error] [pid 3217131:tid 3217135] [client 2a0b:f4c2::16:16526] [client 2a0b:f4c2::16] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sallykimmel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sallykimmel.com"] [uri "/administrator/backups/database.sql"] [unique_id "aDOb8ZNwdWx3gHiK2yEXvgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-25 06:46:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::16 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 25 02:46:04.136137 2025] [security2:error] [pid 2203404:tid 2203404] [client 2a0b:f4c2::16:5100] [client 2a0b:f4c2::16] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||investorsfundingusa.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "investorsfundingusa.com"] [uri "/rsfundingusa-2022.sql"] [unique_id "aDK8rKu8vDEcQ6wOLSCxUwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack