๐บ๐ธ
TPI-Abuse
2025-01-26 09:13:01
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 26 04:12:53.160370 2025] [security2:error] [pid 24500:tid 24500] [client 2a0b:f4c2::26:8350] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lawrencehale.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lawrencehale.net"] [uri "/db.sql"] [unique_id "Z5X8lRnwvZ9DtelIYIpUWwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Nicolmn
2025-01-10 00:14:40
(1 year ago)
Web form spam ( id mlsn-mm.l )
Web Spam
๐บ๐ธ
TPI-Abuse
2024-12-11 21:25:05
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 11 16:24:58.196520 2024] [security2:error] [pid 25599:tid 25599] [client 2a0b:f4c2::26:28982] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.advantagept.org"] [uri "/.git/config"] [unique_id "Z1oDKs2sfeQdtM85uTwkPwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-04 08:35:36
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 04 03:35:31.038576 2024] [security2:error] [pid 25586:tid 25586] [client 2a0b:f4c2::26:30872] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||enduratuff.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "enduratuff.com"] [uri "/backups.sql"] [unique_id "Z1AUU4UzywzXw9jbZ011pwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-28 15:35:26
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 28 10:35:23.231362 2024] [security2:error] [pid 2530704:tid 2530704] [client 2a0b:f4c2::26:10478] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.leggett.k12.ca.us"] [uri "/.git/config"] [unique_id "Z0iNu6qBYHCp_ng9THgzpQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-21 00:08:57
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 20 19:08:51.583258 2024] [security2:error] [pid 10395:tid 10395] [client 2a0b:f4c2::26:33792] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.wholekr.com"] [uri "/.git/config"] [unique_id "Zz56E0lzWq5L4yNtRNop3AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-09 12:50:03
(1 year ago)
| Multiple common web attacks from same source ip. (multiple servers)
Hacking
SQL Injection
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2024-11-02 15:11:00
(1 year ago)
Probing for Wordpress vulnerabilities
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2024-09-24 05:25:54
(1 year ago)
Triggered Cloudflare WAF (firewallCustom).
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET) [T1]
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom).
Action taken: BLOCK
ASN: 60729 (TORSERVERS-NET) [T1]
Protocol: HTTP/2 (method GET)
Domain: sefinek.net
Endpoint: /favicon.ico
Timestamp: 2024-09-23T21:11:21Z
Ray ID: 8c7d86d4996cca2f
Rule ID: 61a9aeb040004a25a09c35e9bfb80913
UA: Mozilla/5.0 (Windows NT 10.0; rv:109.0) Gecko/20100101 Firefox/115.0
Report generated by Node-Cloudflare-WAF-AbuseIPDB https://github.com/sefinek24/Node-Cloudflare-WAF-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
myagent.site
2024-09-17 22:36:13
(2 years ago)
Blocking for trying to access an exploit file: /config.php~
Hacking
๐บ๐ธ
TPI-Abuse
2024-08-31 02:58:47
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 30 22:58:42.184814 2024] [security2:error] [pid 24560:tid 24560] [client 2a0b:f4c2::26:7744] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||reyadecostarica.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "reyadecostarica.com"] [uri "/starica.sql"] [unique_id "ZtKG4gxr8Wksh1ekSJEuagAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-30 12:58:25
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 30 08:58:18.057386 2024] [security2:error] [pid 19928:tid 19928] [client 2a0b:f4c2::26:34400] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.printorganic.com"] [uri "/.git/config"] [unique_id "ZtHB6qValxZiiS5kfsWd_AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MacLotsen
2024-08-28 17:46:48
(2 years ago)
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3 ...
show more
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (SS; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.2.20"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-log
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Admins@FBN
2024-08-20 06:05:43
(2 years ago)
FW-PortScan: Traffic Blocked srcport=58350 dstport=443
Port Scan
๐บ๐ธ
TPI-Abuse
2024-08-18 21:28:41
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 17:28:35.270821 2024] [security2:error] [pid 8055:tid 8055] [client 2a0b:f4c2::26:33250] [client 2a0b:f4c2::26] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.iyp-home.com"] [uri "/.git/config"] [unique_id "ZsJng_E3KdPZ8t6oUS_aRQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack