๐บ๐ธ
TPI-Abuse
2025-09-20 07:43:33
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 20 03:43:24.437510 2025] [security2:error] [pid 19864:tid 19864] [client 2a0b:f4c2::18:9484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||saadeh.ws|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "saadeh.ws"] [uri "/s.sql"] [unique_id "aM5bHO2fp_XaHH6WyLJD2gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-18 10:37:01
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 18 06:36:51.925304 2025] [security2:error] [pid 7228:tid 7228] [client 2a0b:f4c2::18:7324] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ashtangayogamelbourne.com.au|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ashtangayogamelbourne.com.au"] [uri "/gamelbourne_com.sql"] [unique_id "aMvgw3h2uGIwL6HTHF-xowAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-17 19:24:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 15:24:35.473379 2025] [security2:error] [pid 14383:tid 14383] [client 2a0b:f4c2::18:48228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebradleyclinic.com"] [uri "/app/.env"] [unique_id "aMsK80dZWGSp44C1Xxy4bwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-17 09:13:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 05:13:44.607699 2025] [security2:error] [pid 161065:tid 161113] [client 2a0b:f4c2::18:6352] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sparkhypnotherapy.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sparkhypnotherapy.com"] [uri "/ypnotherapy.sql"] [unique_id "aMp7yBpNNWuesLGm8UvI8gAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-17 02:31:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 22:31:29.731401 2025] [security2:error] [pid 18165:tid 18165] [client 2a0b:f4c2::18:15742] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||radicalchange.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "radicalchange.org"] [uri "/nge.sql"] [unique_id "aModgfyDv0ko5JlzOR8gtAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-16 21:26:12
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 16 17:26:06.959646 2025] [security2:error] [pid 8933:tid 8933] [client 2a0b:f4c2::18:26614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bebloor.ca"] [uri "/.env"] [unique_id "aMnV7ks5GdUzLjFSUitkMgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-09-07 17:46:03
(1 year ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-07 07:31:36
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 03:31:29.773614 2025] [security2:error] [pid 3247:tid 3247] [client 2a0b:f4c2::18:20000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.airtechconsulting.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.airtechconsulting.com"] [uri "/wordpress.sql"] [unique_id "aL000XG7g2CjPpNsrEqqLQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 04:14:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 00:14:54.145921 2025] [security2:error] [pid 28854:tid 28854] [client 2a0b:f4c2::18:33316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kinderland-preschool.com"] [uri "/wp-config.php.zip"] [unique_id "aL0GvvdwpN1Ez2uVKfZGqAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 03:23:25
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 23:23:19.517890 2025] [security2:error] [pid 30503:tid 30503] [client 2a0b:f4c2::18:29446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.d-sinema.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.d-sinema.com"] [uri "/d-.sql"] [unique_id "aLz6p317a8l85b92w_c8iQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-04 16:34:21
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 04 12:34:14.552409 2025] [security2:error] [pid 26589:tid 26693] [client 2a0b:f4c2::18:63852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alancphotography.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alancphotography.com"] [uri "/tography_com.sql"] [unique_id "aLm_hkVtsRv58iHf7nTQowAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
1gz
2025-09-03 00:31:53
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST me ...
show more
Triggered Cloudflare WAF (firewallCustom) from T1.
Action taken: CHALLENGE
Protocol: HTTP/2 (POST method)
Endpoint: /auth/login
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.0) Gecko/20100101 Firefox/128.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-09-02 09:11:46
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 05:11:40.510238 2025] [security2:error] [pid 29696:tid 29696] [client 2a0b:f4c2::18:7686] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gilgoinn.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gilgoinn.com"] [uri "/gilgoi.sql"] [unique_id "aLa0zI925Dr5HN7G9N_lTQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-31 04:16:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 31 00:16:28.024009 2025] [security2:error] [pid 23483:tid 23483] [client 2a0b:f4c2::18:12642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||monogay.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "monogay.org"] [uri "/onogay.sql"] [unique_id "aLPMnIS_d4nLJ6jln-BzewAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-29 23:32:44
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::18 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 29 19:32:36.650765 2025] [security2:error] [pid 18347:tid 18347] [client 2a0b:f4c2::18:54254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tedharris.com"] [uri "/wp-config.php.zip"] [unique_id "aLI4lIxcvQb9skGxEptUnQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack