๐บ๐ธ
TPI-Abuse
2025-08-28 03:11:06
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 27 23:11:03.049446 2025] [security2:error] [pid 16112:tid 16112] [client 2a0b:f4c2::21:38460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michelehoop.com"] [uri "/wp-config.php.zip"] [unique_id "aK_Ix25X-pUkSrjUEmd4PQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Kinsei Engineering Inc.
2025-08-26 05:40:15
(11 months ago)
nginx:Illicit login attempts to the CMS, or investigation into CMS plugins with vulnerabilities.
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-25 13:35:51
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 25 09:35:44.896824 2025] [security2:error] [pid 5579:tid 5579] [client 2a0b:f4c2::21:40780] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||salernospizza.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salernospizza.com"] [uri "/zza.sql"] [unique_id "aKxmsGNS4kxO9cLtHaseXAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-19 23:01:03
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 19 19:00:58.985534 2025] [security2:error] [pid 22932:tid 22932] [client 2a0b:f4c2::21:21726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.blacksheepoffroad.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.blacksheepoffroad.com"] [uri "/blacksheepoffro.sql"] [unique_id "aKUCKksrKzZkMrrip42YeQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-16 02:48:05
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 15 22:47:58.847613 2025] [security2:error] [pid 14962:tid 14962] [client 2a0b:f4c2::21:31284] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bonnesfrequences.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bonnesfrequences.com"] [uri "/bonne.sql"] [unique_id "aJ_xXuw-nz7x5__CzsCM1gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-15 02:35:27
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 14 22:35:19.000858 2025] [security2:error] [pid 16791:tid 16791] [client 2a0b:f4c2::21:14158] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ewingmissouri.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ewingmissouri.com"] [uri "/e.sql"] [unique_id "aJ6c5qq9wenT04_zzqea4QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-25 15:11:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 25 11:11:33.774947 2025] [security2:error] [pid 700935:tid 700935] [client 2a0b:f4c2::21:26882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||concentricsteel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "concentricsteel.com"] [uri "/2021.sql"] [unique_id "aFwRpS8NoS8Vi7zMzUywrQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-24 01:35:43
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 23 21:35:34.815198 2025] [security2:error] [pid 3513446:tid 3513446] [client 2a0b:f4c2::21:18032] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||doctorspainmanagement.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doctorspainmanagement.com"] [uri "/2022_agement.sql"] [unique_id "aFoA5uHOIXBLQEiBxvEViwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-19 00:34:20
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 18 20:34:13.792578 2025] [security2:error] [pid 619879:tid 619879] [client 2a0b:f4c2::21:60694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neconebooks.com"] [uri "/wp-config.php.bak.a2"] [unique_id "aFNbBUq0I6K4BmzZeuGPnQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-16 22:16:02
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 18:15:56.212045 2025] [security2:error] [pid 3030299:tid 3030333] [client 2a0b:f4c2::21:51940] [client 2a0b:f4c2::21] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boxvalleyrockers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boxvalleyrockers.com"] [uri "/administrator/backups/database.sql"] [unique_id "aCe5HBP5_e6pwaUuz4Y2-AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-15 10:23:42
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 06:23:33.365273 2025] [security2:error] [pid 1896557:tid 1896660] [client 2a0b:f4c2::21:2966] [client 2a0b:f4c2::21] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oilchangelafayette.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oilchangelafayette.com"] [uri "/2022_afayette.sql"] [unique_id "aCXApQztWTnWQzAtUVVMeAAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-15 02:44:35
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 14 22:44:31.468002 2025] [security2:error] [pid 3978451:tid 3978451] [client 2a0b:f4c2::21:46062] [client 2a0b:f4c2::21] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||muziktellers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "muziktellers.com"] [uri "/adminer.sql"] [unique_id "aCVVD5xRqfZfP4ziS45rMQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-07 13:18:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 09:18:16.459270 2025] [security2:error] [pid 783125:tid 783125] [client 2a0b:f4c2::21:21054] [client 2a0b:f4c2::21] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clickablebonus.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clickablebonus.com"] [uri "/adminer.sql"] [unique_id "aBtdmDoFSJni5Jw2mW5vbgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-07 09:52:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 05:52:48.935074 2025] [security2:error] [pid 2812021:tid 2812164] [client 2a0b:f4c2::21:21358] [client 2a0b:f4c2::21] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sloveniaflyfishing.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sloveniaflyfishing.com"] [uri "/bd.sql"] [unique_id "aBstcBYG4_0sl04F06lbKwAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-06 08:39:56
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::21 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 04:39:49.196813 2025] [security2:error] [pid 1925784:tid 1925784] [client 2a0b:f4c2::21:43234] [client 2a0b:f4c2::21] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||smilingorc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smilingorc.com"] [uri "/adminer.sql"] [unique_id "aBnK1SZ3PYhZ21edNj1BXQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack