๐บ๐ธ
TPI-Abuse
2025-11-03 01:44:01
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 02 20:43:56.212386 2025] [security2:error] [pid 31543:tid 31543] [client 2a0b:f4c2::22:23964] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||pschitchat.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pschitchat.com"] [uri "/at.sql"] [unique_id "aQgI3EDqKvssQNWy-X5wpwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-27 00:57:16
(10 months ago)
(modsecurity) srv101 ModSecurity 2a0b:f4c2::22 (Unknown): 5 in the last 3600 secs; Ports: *; Directi ...
show more
(modsecurity) srv101 ModSecurity 2a0b:f4c2::22 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-26 04:22:06
(10 months ago)
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::22 (Unknown): 1 in the last 3600 secs; Ports: *; Dir ...
show more
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::22 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-19 12:05:42
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 19 08:05:39.213790 2025] [security2:error] [pid 31302:tid 31302] [client 2a0b:f4c2::22:59602] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||modalguitarist.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "modalguitarist.com"] [uri "/mo.sql"] [unique_id "aPTUEzgEmZxEUPLh9rKkSAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-17 01:27:48
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 21:27:42.550140 2025] [security2:error] [pid 21066:tid 21066] [client 2a0b:f4c2::22:32432] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mavikalem.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mavikalem.org"] [uri "/alem.sql"] [unique_id "aPGbju6mpSs0xGSLvrU30wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-14 11:39:47
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 14 07:39:40.177777 2025] [security2:error] [pid 4109:tid 4109] [client 2a0b:f4c2::22:59412] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||therocketmice.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "therocketmice.com"] [uri "/thero.sql"] [unique_id "aO42fKuhpri4ngZZnfh2_AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-11 14:46:58
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 10:46:52.983074 2025] [security2:error] [pid 4724:tid 4724] [client 2a0b:f4c2::22:58808] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casadelsolmexico.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casadelsolmexico.net"] [uri "/olmexico.sql"] [unique_id "aOpt3NUr6Jf07p0hsyY6bwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-11 10:14:23
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 06:14:19.938692 2025] [security2:error] [pid 2606:tid 2606] [client 2a0b:f4c2::22:2168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qed-consulting.co"] [uri "/wp-config.php~"] [unique_id "aOot-4OqFnXysp0L9_UTNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-10 17:05:54
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 13:05:49.094165 2025] [security2:error] [pid 11615:tid 11777] [client 2a0b:f4c2::22:29328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||trulyoriginalpurpleoctopus.art|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trulyoriginalpurpleoctopus.art"] [uri "/lpurpleoctopus.sql"] [unique_id "aOk87QpXr3l5AZuhREnL1QAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Ribeye375
2025-10-09 21:20:18
(11 months ago)
HIPS recon-attempt - Block tcp/0:65535
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 20:19:15
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 16:19:07.369651 2025] [security2:error] [pid 26055:tid 26055] [client 2a0b:f4c2::22:52092] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||rachelfia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rachelfia.com"] [uri "/elfia.sql"] [unique_id "aOgYu8ykdjJe0hXNZaufMgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-10-04 07:44:47
(11 months ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 23:47:37
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 19:47:34.156120 2025] [security2:error] [pid 16517:tid 16517] [client 2a0b:f4c2::22:63010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pngtravel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pngtravel.com"] [uri "/avel.sql"] [unique_id "aN8PFlZGuA5imb6c8hME9QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-02 14:55:17
(11 months ago)
2a0b:f4c2::22 - - [02/Oct/2025:14:55:16 +0000] "GET /.env HTTP/1.1" 404 40642 "-" "python-requests/2 ...
show more
2a0b:f4c2::22 - - [02/Oct/2025:14:55:16 +0000] "GET /.env HTTP/1.1" 404 40642 "-" "python-requests/2.32.3"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 11:27:19
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 07:27:13.608299 2025] [security2:error] [pid 5711:tid 5711] [client 2a0b:f4c2::22:40818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.eran.construction|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.eran.construction"] [uri "/n.sql"] [unique_id "aN5hkUuKHZFXOGhUtUl0BQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack