๐บ๐ธ
TPI-Abuse
2025-11-12 04:35:19
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 23:35:14.451571 2025] [security2:error] [pid 22328:tid 22328] [client 2a0b:f4c2::19:42870] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rimaine.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rimaine.org"] [uri "/rimain.sql"] [unique_id "aRQOgr-8j6J0iq1UfInDGQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-12 03:13:42
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 22:13:38.515037 2025] [security2:error] [pid 14461:tid 14461] [client 2a0b:f4c2::19:11744] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||investorscalifornia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "investorscalifornia.com"] [uri "/backups.sql"] [unique_id "aRP7YnnEUUhzGxq4jccHdgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 06:42:10
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 01:42:00.352406 2025] [security2:error] [pid 21367:tid 21393] [client 2a0b:f4c2::19:18882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||managementlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "managementlaw.com"] [uri "/w.sql"] [unique_id "aRLauCpCAO0LqPGp3bdXKwAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2025-11-10 17:44:46
(9 months ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 07:01:46
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 02:01:38.586358 2025] [security2:error] [pid 8496:tid 8496] [client 2a0b:f4c2::19:47776] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serranoscoffee.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serranoscoffee.com"] [uri "/serra.sql"] [unique_id "aQxH0l9Y0VRVonjK2lxtvwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-30 20:12:41
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 16:12:34.759650 2025] [security2:error] [pid 19473:tid 19473] [client 2a0b:f4c2::19:38994] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||indiahouseportland.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "indiahouseportland.com"] [uri "/wp.sql"] [unique_id "aQPGsjxInRCE8Bs3nMbQCgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
R.G.
2025-10-28 15:32:42
(9 months ago)
2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org), 5 distributed directadmin attacks on account [cloac ...
show more
2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org), 5 distributed directadmin attacks on account [cloacked] in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_DISTATTACK; Logs: Oct 28 16:32:31 user denied: wordpress (mysql-denied) from 2a14:c380:50:20::a
show less
Brute-Force
๐ณ๐ฑ
Mangelot Hosting
2025-10-26 06:26:49
(9 months ago)
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::19 (Unknown): 1 in the last 3600 secs; Ports: *; Dir ...
show more
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::19 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-20 19:30:18
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 20 15:30:10.277046 2025] [security2:error] [pid 31636:tid 31636] [client 2a0b:f4c2::19:24222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gegkal.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gegkal.com"] [uri "/gegka.sql"] [unique_id "aPaNwkcRxO2KH3Xx271vogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 07:39:24
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 03:39:18.644806 2025] [security2:error] [pid 23865:tid 23865] [client 2a0b:f4c2::19:30222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tedharris.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tedharris.com"] [uri "/wordpress.sql"] [unique_id "aOdmppRHYxzIMG86-IHpjAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-05 19:21:44
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 15:21:39.082919 2025] [security2:error] [pid 19290:tid 19290] [client 2a0b:f4c2::19:19990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.surviquo.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.surviquo.com"] [uri "/wordpress.sql"] [unique_id "aOLFQ1ltDcX9HUMyxOoDMAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-10-05 18:11:58
(10 months ago)
WP_EXPLOIT_PROBE WP_MALWARE_PROBE
Hacking
Web App Attack
Anonymous
2025-10-04 16:31:24
(10 months ago)
Failed login attempt detected by Fail2Ban in recidive jail
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-03 22:09:51
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 18:09:44.204973 2025] [security2:error] [pid 31534:tid 31534] [client 2a0b:f4c2::19:44048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gangnagel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gangnagel.com"] [uri "/.sql"] [unique_id "aOBJqAhpRXkGEj5Wer44awAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 05:33:48
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 01:33:42.177749 2025] [security2:error] [pid 14160:tid 14281] [client 2a0b:f4c2::19:40834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clearwaterpumpservices.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clearwaterpumpservices.com"] [uri "/learwaterpumpservices_com.sql"] [unique_id "aNy9NqZdMz98P5goItFJmgAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack