๐บ๐ธ
ipblock.com
2026-02-27 00:43:00
(5 months ago)
IPBlock protected site ID [3717-sec].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 03:44:38
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 22:44:32.497188 2026] [security2:error] [pid 3954:tid 3954] [client 2a0b:f4c2::22:11532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bullardrealtync.com"] [uri "/.git/config"] [unique_id "aZvNIBK6HYcw7qY1lPrvbgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-01-31 23:01:20
(5 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-30.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-28 22:04:33
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 28 17:04:26.674924 2026] [security2:error] [pid 30269:tid 30269] [client 2a0b:f4c2::22:45378] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jaynawilliamsrealty.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jaynawilliamsrealty.com"] [uri "/jaynawilli.sql"] [unique_id "aXqH6lV-9fPfu1cLSqjUhgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 20:18:17
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 15:18:08.212377 2026] [security2:error] [pid 2376:tid 2376] [client 2a0b:f4c2::22:19298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.zorganizing.com"] [uri "/.git/config"] [unique_id "aXfMAJlxXMbUj3Tvu1Y6LgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-26 03:40:08
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 25 22:40:04.781735 2026] [security2:error] [pid 22052:tid 22052] [client 2a0b:f4c2::22:35210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.konar-steenberg.com"] [uri "/.git/config"] [unique_id "aXbiFK_hGb2JHRTnDOeUbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-21 22:08:30
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 21 17:08:24.436394 2026] [security2:error] [pid 11638:tid 11638] [client 2a0b:f4c2::22:41472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bluegrassexpressband.com"] [uri "/.git/config"] [unique_id "aXFOWJu7mJ2p4l_fpXQz_AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 05:58:09
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 00:58:03.689313 2026] [security2:error] [pid 22007:tid 22007] [client 2a0b:f4c2::22:30856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nypatriotcards.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nypatriotcards.com"] [uri "/s_com.sql"] [unique_id "aWcwa8v99pOGlax3L5UdhwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-12 12:08:58
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 12 07:08:51.237896 2026] [security2:error] [pid 20675:tid 20675] [client 2a0b:f4c2::22:31592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.livinghopehighschool.org"] [uri "/.git/config"] [unique_id "aWTkUzOIU-motfK0hbyDbQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2026-01-05 01:40:41
(6 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-04 00:49:33
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 19:49:28.339736 2026] [security2:error] [pid 20224:tid 20224] [client 2a0b:f4c2::22:23416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theseoscribe.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theseoscribe.com"] [uri "/ribe_com.sql"] [unique_id "aVm5GGNER34OhvjjETlO7QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-01-03 17:18:00
(6 months ago)
IPBlock protected site ID [3192-af][s=06].
Rogue crawler, does not respect robots.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-02 13:12:36
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 08:12:30.844154 2026] [security2:error] [pid 4364:tid 4382] [client 2a0b:f4c2::22:63956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||landmarkocchealth.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "landmarkocchealth.com"] [uri "/bck.sql"] [unique_id "aVfEPq_QFQKsTNV9rEZp2QAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-02 04:52:22
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 23:52:18.878016 2026] [security2:error] [pid 2111:tid 2111] [client 2a0b:f4c2::22:38752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raintechgutters.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raintechgutters.com"] [uri "/ra.sql"] [unique_id "aVdPAl30-Be6r-0gE3xdZAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 18:20:39
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 13:20:31.341228 2026] [security2:error] [pid 31306:tid 31306] [client 2a0b:f4c2::22:36176] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||doreenkimura.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doreenkimura.com"] [uri "/latest.sql"] [unique_id "aVa67w0DoZk-Ve4vmSWyHQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack