πΊπΈ
TPI-Abuse
2025-09-30 17:17:08
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 13:17:04.641457 2025] [security2:error] [pid 17636:tid 17636] [client 2a0b:f4c2::19:31104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||souldata.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "souldata.com"] [uri "/a.sql"] [unique_id "aNwQkPK6BPsGc4JPS-YW_wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
β¨
2025-09-29 13:50:02
(10 months ago)
Domain : mitiendaonline.net
Rule : xmlrpc
2025-09-29 13:49:07 152.53.151.170 GET /xmlrpc.php - 80 - ...
show more
Domain : mitiendaonline.net
Rule : xmlrpc
2025-09-29 13:49:07 152.53.151.170 GET /xmlrpc.php - 80 - 104.23.199.96 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0 - mitiendaonline.net 404 0 0 10565 616 115 - 2a0b:f4c2::19
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-28 08:21:11
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 28 04:21:07.699205 2025] [security2:error] [pid 5226:tid 5226] [client 2a0b:f4c2::19:33778] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.robinsnestingplace.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.robinsnestingplace.net"] [uri "/robi.sql"] [unique_id "aNjv8_A2SBAQLVCPzKFB-gAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-27 04:27:23
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 27 00:27:15.762253 2025] [security2:error] [pid 4884:tid 4884] [client 2a0b:f4c2::19:30358] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||adlc18.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adlc18.org"] [uri "/c18.sql"] [unique_id "aNdnoxSlMHNP_Oh778amAwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-23 16:30:10
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 23 12:30:03.691424 2025] [security2:error] [pid 21401:tid 21424] [client 2a0b:f4c2::19:22256] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||teritemme.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teritemme.com"] [uri "/mme.sql"] [unique_id "aNLLC-P2UJdAWvmGIN5uhwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-19 14:28:36
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 19 10:28:29.629938 2025] [security2:error] [pid 26966:tid 26966] [client 2a0b:f4c2::19:54440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vanmeer.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vanmeer.info"] [uri "/wordpress.sql"] [unique_id "aM1ojULrTU6XAD19oP0NtgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-14 15:10:27
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 14 11:10:20.638650 2025] [security2:error] [pid 19160:tid 19160] [client 2a0b:f4c2::19:51838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hodlmoser.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hodlmoser.com"] [uri "/hodl.sql"] [unique_id "aMba3PBk-lA629mTnLSpewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-14 03:10:27
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 13 23:10:19.922050 2025] [security2:error] [pid 3357557:tid 3357582] [client 2a0b:f4c2::19:11430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ward-bergerhouse.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ward-bergerhouse.org"] [uri "/wordpress.sql"] [unique_id "aMYyG7qcJfVSqKG0mFcAnwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-09 06:20:50
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 09 02:20:42.162557 2025] [security2:error] [pid 10212:tid 10212] [client 2a0b:f4c2::19:51914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handmrenovationsllc.com"] [uri "/wp-config.php.zip"] [unique_id "aL_HOvkDWSJ7_hyvONVMVwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dtorrer
2025-09-08 21:15:19
(11 months ago)
General vulnerability scan.
Port Scan
πΊπΈ
TPI-Abuse
2025-09-07 20:28:47
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 16:28:42.163919 2025] [security2:error] [pid 15024:tid 15024] [client 2a0b:f4c2::19:30288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthtwoworkshop.com"] [uri "/wp-config.php.zip"] [unique_id "aL3q-tTI2paU8Gy32FxYRgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-06 08:59:26
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 04:59:20.342387 2025] [security2:error] [pid 23714:tid 23714] [client 2a0b:f4c2::19:36242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lenorasflowers.com"] [uri "/wp-config.php.zip"] [unique_id "aLv36OgnlZgGB4BHx2hlLQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dtorrer
2025-09-06 04:45:56
(11 months ago)
General vulnerability scan.
Port Scan
πΊπΈ
TPI-Abuse
2025-09-05 04:47:44
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::19 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 05 00:47:37.213092 2025] [security2:error] [pid 31472:tid 31472] [client 2a0b:f4c2::19:28738] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||onlinesuretybonds.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "onlinesuretybonds.com"] [uri "/onlinesuretybon.sql"] [unique_id "aLprafW6CBrx_qCdPcLGPwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2025-09-05 04:10:18
(11 months ago)
Probing for application vulnerabilities
Brute-Force
Web App Attack