๐บ๐ธ
TPI-Abuse
2025-02-21 08:52:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 21 03:52:09.723368 2025] [security2:error] [pid 1563:tid 1563] [client 2a0b:f4c2::22:64426] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bigheartskitchen.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bigheartskitchen.net"] [uri "/mysql.sql"] [unique_id "Z7g-ud_-zx10Oq038Agu2gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-17 13:55:44
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 17 08:55:39.136204 2025] [security2:error] [pid 3363:tid 3363] [client 2a0b:f4c2::22:12704] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blacksheepoffroad.com"] [uri "/sftp-config.json"] [unique_id "Z7M_23LLgZLTp8ibGXGbuQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-15 13:58:02
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 15 08:57:55.549755 2025] [security2:error] [pid 891:tid 908] [client 2a0b:f4c2::22:38650] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dontbeajerklikeyourwork.com"] [uri "/downl.php"] [unique_id "Z7CdY2zpHlilFyn237Ho_QAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-11 00:16:39
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 10 19:16:33.076180 2025] [security2:error] [pid 3823825:tid 3823825] [client 2a0b:f4c2::22:50282] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "golfmastercanada.com"] [uri "/download.php"] [unique_id "Z6qW4WpGs3EfR3F15vi-bQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-01-22 11:00:30
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 22 06:00:20.939476 2025] [security2:error] [pid 19826:tid 19922] [client 2a0b:f4c2::22:63814] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nepsco.com"] [uri "/wp-config.php.bk"] [unique_id "Z5DPxFe6T1iklfrpw0wJ4AAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-01-16 23:13:46
(1 year ago)
2025-01-16 06:11:43 //d3azdm1q0gvo54.cloudfront.net:80
Web App Attack
๐ณ๐ฑ
exxos
2025-01-16 16:27:14
(1 year ago)
php-rapid-access attacks
DDoS Attack
๐ซ๐ท
Nicolmn
2025-01-07 17:28:33
(1 year ago)
Web form spam ( id mmnf.l )
Web Spam
๐ง๐ช
cmbplf
2024-12-28 23:59:05
(1 year ago)
10.602 requests in 1 hour (2d16h59m)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-12-27 11:01:07
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:211190) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 27 06:01:00.280294 2024] [security2:error] [pid 9605:tid 9605] [client 2a0b:f4c2::22:50822] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||nationalenq.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /?umbrella-restore=1&filename=../../../../../../etc/passwd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationalenq.com"] [uri "/"] [unique_id "Z26I7FC21FQCZNZNWnGlJwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-02 11:13:27
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 02 06:13:18.813118 2024] [security2:error] [pid 22182:tid 22189] [client 2a0b:f4c2::22:14894] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.chadcentral.com"] [uri "/.git/config"] [unique_id "Z02WTujRJsh_xNY7kSwKcQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-21 06:16:38
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 21 01:16:33.350262 2024] [security2:error] [pid 15424:tid 15424] [client 2a0b:f4c2::22:15396] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brbcoin.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brbcoin.com"] [uri "/wp-config.backup"] [unique_id "Zz7QQfkl3oPoUwKd6PEQ4gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-20 01:46:51
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 20:46:43.788707 2024] [security2:error] [pid 16816:tid 16816] [client 2a0b:f4c2::22:45174] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.technesa.com"] [uri "/.git/config"] [unique_id "Zz0_g2x2dwVLoCgL44pKZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-09 16:53:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 09 12:53:44.233883 2024] [security2:error] [pid 8891:tid 8891] [client 2a0b:f4c2::22:15764] [client 2a0b:f4c2::22] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alejandrogorsse.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alejandrogorsse.com"] [uri "/jandrogorsse.sql"] [unique_id "Zwa1GOO5Du5Lre4Ra3hJDwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MacLotsen
2024-08-28 17:47:20
(2 years ago)
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3 ...
show more
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (SS; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.2.20"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-log
...
show less
Brute-Force
Web App Attack