๐บ๐ธ
TPI-Abuse
2025-12-05 10:54:53
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 05 05:54:44.320801 2025] [security2:error] [pid 30385:tid 30385] [client 2a0b:f4c2::18:64950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||karenbernsteinlaw.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "karenbernsteinlaw.net"] [uri "/kare.sql"] [unique_id "aTK59L2JlSu-0Gkb8CcN7QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 04:39:18
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 23:39:15.348238 2025] [security2:error] [pid 26092:tid 26092] [client 2a0b:f4c2::18:37634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||majesticsolutions.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "majesticsolutions.co"] [uri "/icsolutions_com.sql"] [unique_id "aTJh84ebgioG3JQWN5PCdgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-05 03:38:40
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 22:38:32.612239 2025] [security2:error] [pid 27219:tid 27219] [client 2a0b:f4c2::18:27986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jeannieksmith.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeannieksmith.com"] [uri "/eannieksmith_com.sql"] [unique_id "aTJTuKF7DNPaiubqrw1LOAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-04 20:32:09
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 04 15:32:00.481619 2025] [security2:error] [pid 21719:tid 21719] [client 2a0b:f4c2::18:62366] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leirstein.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leirstein.com"] [uri "/leirstein_com.sql"] [unique_id "aTHvwHxD5Nscy2aiQjfqUgAAAHo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-30 00:10:54
(9 months ago)
[Sun Nov 30 01:10:50.394671 2025] [authz_core:error] [pid 280940:tid 136203331446464] [remote 2a0b:f ...
show more
[Sun Nov 30 01:10:50.394671 2025] [authz_core:error] [pid 280940:tid 136203331446464] [remote 2a0b:f4c2::18:36948] AH01630: client denied by server configuration: /var/www/katrinzeidler.com/katrinzeidler.sql [Sun Nov 30 01:10:51.646228 2025] [authz_core:error] [pid 302215:tid 136203297875648] [remote 2a0b:f4c2::18:36964] AH01630: client denied by server configuration: /var/www/katrinzeidler.com/wordpress.sql [Sun Nov 30 01:10:52.950270 2025] [authz_core:error] [pid 291887:tid 136203154978496] [remote 2a0b:f4c2::18:36986] AH01630: client denied by server configuration: /var/www/katrinzeidler.com/daily.sql
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-23 16:18:30
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 11:18:22.081572 2025] [security2:error] [pid 25715:tid 25715] [client 2a0b:f4c2::18:42774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelthompson.biz|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelthompson.biz"] [uri "/backups.sql"] [unique_id "aSMzzsbkn_ViAgtQU1Oz5QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 06:40:07
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 01:39:59.874069 2025] [security2:error] [pid 12698:tid 12698] [client 2a0b:f4c2::18:3626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lcoor.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lcoor.org"] [uri "/l.sql"] [unique_id "aSAJP6SXz7lRS9MLo3v54AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-20 15:49:36
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 10:49:28.767285 2025] [security2:error] [pid 2333:tid 2339] [client 2a0b:f4c2::18:25716] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||property-management-companies-chicago.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "property-management-companies-chicago.com"] [uri "/property-management-companies-chi.sql"] [unique_id "aR84iPcONrwy4Ml_bMoB3QAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-20 11:40:07
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 06:40:00.024266 2025] [security2:error] [pid 2090193:tid 2090215] [client 2a0b:f4c2::18:16054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||miraclebrow.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "miraclebrow.com"] [uri "/ebrow.sql"] [unique_id "aR7-ENW5-bhVg6E7k13AUgAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2025-11-14 19:57:37
(10 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 01:08:41
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 12 20:08:35.468280 2025] [security2:error] [pid 17550:tid 17550] [client 2a0b:f4c2::18:12884] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nolaanime.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nolaanime.com"] [uri "/config.backup"] [unique_id "aRUvk0Mmz3nhzu_dgU40JAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-11-12 11:41:41
(10 months ago)
(modsecurity) srv103 ModSecurity 2a0b:f4c2::18 (Unknown): 5 in the last 3600 secs; Ports: *; Directi ...
show more
(modsecurity) srv103 ModSecurity 2a0b:f4c2::18 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 07:17:50
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 02:17:47.332799 2025] [security2:error] [pid 24686:tid 24686] [client 2a0b:f4c2::18:14324] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rentkase.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rentkase.com"] [uri "/rentkas.sql"] [unique_id "aRGRm9QVcjAfGtLKGrg-JwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-30 21:36:38
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 17:36:33.846318 2025] [security2:error] [pid 8186:tid 8186] [client 2a0b:f4c2::18:1624] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mikedeutsch.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mikedeutsch.com"] [uri "/mikedeu.sql"] [unique_id "aQPaYVYf_k0ptboOztKNnAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-30 09:57:43
(10 months ago)
(modsecurity) srv103 ModSecurity 2a0b:f4c2::18 (Unknown): 5 in the last 3600 secs; Ports: *; Directi ...
show more
(modsecurity) srv103 ModSecurity 2a0b:f4c2::18 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack