๐บ๐ธ
TPI-Abuse
2025-10-18 07:42:51
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 18 03:42:43.936776 2025] [security2:error] [pid 3208:tid 3208] [client 2a0b:f4c2::26:51762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fatbastardcompetition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fatbastardcompetition.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aPNE8-_Dk_g4Y7WeCKWJpwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-12 10:31:46
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 12 06:31:39.543637 2025] [security2:error] [pid 12150:tid 12150] [client 2a0b:f4c2::26:48096] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||circleinthesquare.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circleinthesquare.org"] [uri "/nthesquare.sql"] [unique_id "aOuDi2DaIQGz8os5gS8UugAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-12 04:32:34
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 12 00:32:27.717286 2025] [security2:error] [pid 5225:tid 5225] [client 2a0b:f4c2::26:22326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ideaofauniversity.website|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ideaofauniversity.website"] [uri "/idea.sql"] [unique_id "aOsvWwYY5APwDrp2ebJ56AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-08 14:19:59
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 08 10:19:53.320156 2025] [security2:error] [pid 1842:tid 1939] [client 2a0b:f4c2::26:57748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||trulyoriginalpurpleoctopus.art|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trulyoriginalpurpleoctopus.art"] [uri "/backup.sql"] [unique_id "aOZzCWUBeNY-BXj_xQZTWgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2025-10-07 09:02:33
(11 months ago)
Probing for exploits
2a0b:f4c2::26 - - [07/Oct/2025:11:02:27 +0200] "GET /l.sql HTTP/1.1" 301 169 "- ...
show more
Probing for exploits
2a0b:f4c2::26 - - [07/Oct/2025:11:02:27 +0200] "GET /l.sql HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0"
2a0b:f4c2::26 - - [07/Oct/2025:11:02:28 +0200] "GET /wp.sql HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:129.0) Gecko/20100101 Firefox/129.0"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-05 08:35:26
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 04:35:18.765057 2025] [security2:error] [pid 4116:tid 4116] [client 2a0b:f4c2::26:41670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.velvetculture.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.velvetculture.com"] [uri "/lvetculture.sql"] [unique_id "aOItxnVxvglrVdUTrDE4FAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-05 01:19:44
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 21:19:38.780876 2025] [security2:error] [pid 8336:tid 8336] [client 2a0b:f4c2::26:39522] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||greatwesternfirearms.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "greatwesternfirearms.com"] [uri "/greatwester.sql"] [unique_id "aOHHqrNmZDBb-we8J_497gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-04 18:33:41
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 14:33:35.834191 2025] [security2:error] [pid 1485406:tid 1485406] [client 2a0b:f4c2::26:54052] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||darrenj.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "darrenj.com"] [uri "/darre.sql"] [unique_id "aOFof81DPu9vYTvUaXrTPgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 06:53:01
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 02:52:54.866837 2025] [security2:error] [pid 21031:tid 21031] [client 2a0b:f4c2::26:41426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davidharrisgriffith.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davidharrisgriffith.com"] [uri "/davidharris.sql"] [unique_id "aNzPxqfTCB0u-dXdqh6ICgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-29 08:01:45
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 04:01:39.709830 2025] [security2:error] [pid 1813:tid 1813] [client 2a0b:f4c2::26:5090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||justicehoward.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "justicehoward.com"] [uri "/oward.sql"] [unique_id "aNo84_I9x-JFQiz6FrvpeQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-28 10:09:06
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 28 06:09:00.742970 2025] [security2:error] [pid 20276:tid 20276] [client 2a0b:f4c2::26:52574] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitess.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitess.com"] [uri "/daily.sql"] [unique_id "aNkJPGYIoEFNkWrPpxu7OQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-27 06:53:31
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 27 02:53:21.982675 2025] [security2:error] [pid 17494:tid 17494] [client 2a0b:f4c2::26:12552] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||campnecon.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "campnecon.com"] [uri "/wp.sql"] [unique_id "aNeJ4d2wvNdl3-BqEKTl-gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2025-09-27 06:24:04
(11 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-25 05:01:44
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 01:01:39.925527 2025] [security2:error] [pid 545:tid 545] [client 2a0b:f4c2::26:57572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ardath.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ardath.net"] [uri "/ardat.sql"] [unique_id "aNTMs3Fl2qI-Rgy_wXhZPQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-24 14:20:29
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::26 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 10:20:20.528992 2025] [security2:error] [pid 13820:tid 13820] [client 2a0b:f4c2::26:5266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wholesalelivelobsters.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wholesalelivelobsters.com"] [uri "/wholesalelive.sql"] [unique_id "aNP-JAOIQ6SVQkWddSv4IQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack