๐บ๐ธ
TPI-Abuse
2025-10-11 14:46:58
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 10:46:52.983074 2025] [security2:error] [pid 4724:tid 4724] [client 2a0b:f4c2::22:58808] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casadelsolmexico.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casadelsolmexico.net"] [uri "/olmexico.sql"] [unique_id "aOpt3NUr6Jf07p0hsyY6bwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-11 10:14:23
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 06:14:19.938692 2025] [security2:error] [pid 2606:tid 2606] [client 2a0b:f4c2::22:2168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qed-consulting.co"] [uri "/wp-config.php~"] [unique_id "aOot-4OqFnXysp0L9_UTNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-10 17:05:54
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 10 13:05:49.094165 2025] [security2:error] [pid 11615:tid 11777] [client 2a0b:f4c2::22:29328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||trulyoriginalpurpleoctopus.art|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trulyoriginalpurpleoctopus.art"] [uri "/lpurpleoctopus.sql"] [unique_id "aOk87QpXr3l5AZuhREnL1QAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Ribeye375
2025-10-09 21:20:18
(9 months ago)
HIPS recon-attempt - Block tcp/0:65535
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-09 20:19:15
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 09 16:19:07.369651 2025] [security2:error] [pid 26055:tid 26055] [client 2a0b:f4c2::22:52092] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||rachelfia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rachelfia.com"] [uri "/elfia.sql"] [unique_id "aOgYu8ykdjJe0hXNZaufMgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-10-04 07:44:47
(9 months ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 23:47:37
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 19:47:34.156120 2025] [security2:error] [pid 16517:tid 16517] [client 2a0b:f4c2::22:63010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pngtravel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pngtravel.com"] [uri "/avel.sql"] [unique_id "aN8PFlZGuA5imb6c8hME9QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-02 14:55:17
(9 months ago)
2a0b:f4c2::22 - - [02/Oct/2025:14:55:16 +0000] "GET /.env HTTP/1.1" 404 40642 "-" "python-requests/2 ...
show more
2a0b:f4c2::22 - - [02/Oct/2025:14:55:16 +0000] "GET /.env HTTP/1.1" 404 40642 "-" "python-requests/2.32.3"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 11:27:19
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 07:27:13.608299 2025] [security2:error] [pid 5711:tid 5711] [client 2a0b:f4c2::22:40818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.eran.construction|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.eran.construction"] [uri "/n.sql"] [unique_id "aN5hkUuKHZFXOGhUtUl0BQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-27 14:41:55
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 27 10:41:48.688220 2025] [security2:error] [pid 25656:tid 25656] [client 2a0b:f4c2::22:13998] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mobileonlinecasinos.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mobileonlinecasinos.co"] [uri "/wordpress.sql"] [unique_id "aNf3rA4WEvDAWmE9a0bT-AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-25 17:13:13
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 13:13:04.436738 2025] [security2:error] [pid 1614:tid 1614] [client 2a0b:f4c2::22:14044] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rogerheath.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rogerheath.com"] [uri "/rogerhea.sql"] [unique_id "aNV4IJa54ZXsH1tyNnCx9gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-24 07:54:26
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 03:54:17.860581 2025] [security2:error] [pid 1436308:tid 1436409] [client 2a0b:f4c2::22:40280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||property-management.company|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "property-management.company"] [uri "/.sql"] [unique_id "aNOjqQcNief3n4NfxBhALAAAAhY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Globe2
2025-09-23 12:01:03
(10 months ago)
[23/Sep/2025:13:01:00 +0100] wpOSAJA8n0gHuXYI3NbJNMoQ 2a0b:f4c2::22 35754 91.212.212.13 443
[23/Sep/ ...
show more
[23/Sep/2025:13:01:00 +0100] wpOSAJA8n0gHuXYI3NbJNMoQ 2a0b:f4c2::22 35754 91.212.212.13 443
[23/Sep/2025:13:01:00 +0100] wpOSAJA8n0gHuXYI3NbJNMoQ 2a0b:f4c2::22 35754 91.212.212.13 443
[23/Sep/2025:13:01:02 +0100] U2SRPB6A02s5zHoOoDCrllYA 2a0b:f4c2::22 35754 91.212.212.13 443
...
show less
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2025-09-21 17:52:58
(10 months ago)
(mod_security) mod_security (id:949110) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:949110) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-20 07:42:56
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::22 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 20 03:42:49.512520 2025] [security2:error] [pid 21935:tid 21935] [client 2a0b:f4c2::22:58272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drdot.xyz"] [uri "/wp-config.php.zip"] [unique_id "aM5a-SFNUOhx2Mrx2SophwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack