๐บ๐ธ
TPI-Abuse
2025-08-28 17:33:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 28 13:33:50.523827 2025] [security2:error] [pid 23220:tid 23220] [client 2a0b:f4c2::28:61268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||viszin.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "viszin.com"] [uri "/wp.sql"] [unique_id "aLCS_rh6pQ5SVO_dhwJ2WwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-08-24 08:45:35
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-19 20:20:21
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 19 16:20:14.901819 2025] [security2:error] [pid 24345:tid 24345] [client 2a0b:f4c2::28:53000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||psscififilmfest.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "psscififilmfest.org"] [uri "/fest_com.sql"] [unique_id "aKTcfj3J6-yp-AQiKXzRZQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐น
thewww.top
2025-08-18 14:57:00
(1 year ago)
Several attempts for unauthorized access, trying to find whitelisted $_SERVER-values using user-agen ...
show more
Several attempts for unauthorized access, trying to find whitelisted $_SERVER-values using user-agent spoofing techniques
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-16 12:13:31
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 16 08:13:24.660806 2025] [security2:error] [pid 10723:tid 10723] [client 2a0b:f4c2::28:12614] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blacksheepoffroad.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blacksheepoffroad.com"] [uri "/bl.sql"] [unique_id "aKB15Dgz-_RuNMwHICUh5QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-16 15:05:06
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 16 11:04:58.570774 2025] [security2:error] [pid 3938430:tid 3938430] [client 2a0b:f4c2::28:1916] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holistichealth4u2.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holistichealth4u2.com"] [uri "/tichealth4u2.sql"] [unique_id "aFAymujymp9c5vJKRmkPXAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-13 22:40:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 13 18:40:29.102233 2025] [security2:error] [pid 830297:tid 830297] [client 2a0b:f4c2::28:25068] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.waterspell.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.waterspell.net"] [uri "/bd.sql"] [unique_id "aEyo3RD-DuyQ0sspopjo6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-13 16:07:03
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 13 12:06:58.159643 2025] [security2:error] [pid 2505076:tid 2505076] [client 2a0b:f4c2::28:31958] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wave94.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wave94.com"] [uri "/bd.sql"] [unique_id "aExMoqFBaVpUiOOimQPAtwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-05-17 05:45:14
(1 year ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-05-14 03:30:01
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 13 23:29:53.603067 2025] [security2:error] [pid 684678:tid 684678] [client 2a0b:f4c2::28:34920] [client 2a0b:f4c2::28] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||joqlawn.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "joqlawn.com"] [uri "/adminer.sql"] [unique_id "aCQOMcV0pJWrQudTabDcbwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-13 10:39:09
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 13 06:39:01.176015 2025] [security2:error] [pid 1959655:tid 1959655] [client 2a0b:f4c2::28:41380] [client 2a0b:f4c2::28] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinbtcshop.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinbtcshop.com"] [uri "/migration.sql"] [unique_id "aCMhRYpYmsfLLwwMYR_ihgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-10 13:55:48
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 10 09:55:41.191615 2025] [security2:error] [pid 942753:tid 942753] [client 2a0b:f4c2::28:57152] [client 2a0b:f4c2::28] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jeffmasonmusic.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jeffmasonmusic.com"] [uri "/migration.sql"] [unique_id "aB9a3ZKDiQkYmx5LkERXCwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-10 00:09:06
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 09 20:09:01.759977 2025] [security2:error] [pid 2276196:tid 2276196] [client 2a0b:f4c2::28:29488] [client 2a0b:f4c2::28] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||firewoodstudio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "firewoodstudio.com"] [uri "/bd.sql"] [unique_id "aB6ZHaFXw_qmgvHO5au4OwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-05-05 23:04:39
(1 year ago)
2025-05-05 19:51:03 /
2025-05-05 19:51:02 /
2025-05-05 19:51:04 /
2025-05-05 19:50:57 /
2025-05-05 1 ...
show more
2025-05-05 19:51:03 /
2025-05-05 19:51:02 /
2025-05-05 19:51:04 /
2025-05-05 19:50:57 /
2025-05-05 19:51:04 /
2025-05-05 19:50:59 /
2025-05-05 19:51:03 /
2025-05-05 19:50:58 /
2025-05-05 19:51:02 /
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 08:54:18
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::28 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 04:54:13.529368 2025] [security2:error] [pid 746394:tid 746412] [client 2a0b:f4c2::28:2144] [client 2a0b:f4c2::28] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jimpepperfest.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jimpepperfest.net"] [uri "/adminer.sql"] [unique_id "aBh8tZyXlj7LpZ7WMNR05AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack