๐ต๐ฑ
nfsec.pl
2025-08-29 12:35:28
(1 year ago)
2a0b:f4c2::29 - - [29/Aug/2025:14:35:22 +0200] "GET /n.sql HTTP/2.0" 404 24550 "-" "Mozilla/4.0 (com ...
show more
2a0b:f4c2::29 - - [29/Aug/2025:14:35:22 +0200] "GET /n.sql HTTP/2.0" 404 24550 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)"
2a0b:f4c2::29 - - [29/Aug/2025:14:35:23 +0200] "GET /wordpress.sql HTTP/2.0" 404 24599 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)"
2a0b:f4c2::29 - - [29/Aug/2025:14:35:24 +0200] "GET /nfs.sql HTTP/2.0" 404 24578 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.2)"
2a0b:f4c2::29 - - [29/Aug/2025:14:35:26 +0200] "GET /c.sql HTTP/2.0" 404 24654 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04
...
show less
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-27 10:34:50
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 27 06:34:40.574377 2025] [security2:error] [pid 16718:tid 16740] [client 2a0b:f4c2::29:31388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killasgarage.bike"] [uri "/wp-config.php.zip"] [unique_id "aK7fQDY3sf2T7-B2uJoKCwAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-19 22:58:25
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 19 18:58:15.362787 2025] [security2:error] [pid 12765:tid 12765] [client 2a0b:f4c2::29:9198] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.blacksheepoffroad.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.blacksheepoffroad.com"] [uri "/eepoffroad.sql"] [unique_id "aKUBhydUTxe04oLojm-QVAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-23 19:17:25
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 23 15:17:15.199935 2025] [security2:error] [pid 1985111:tid 1985111] [client 2a0b:f4c2::29:54874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nancyscafeandcatering.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nancyscafeandcatering.com"] [uri "/2022-cyscafeandcatering.sql"] [unique_id "aFmoOymnt8N9KV8E2kBEogAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-17 00:05:23
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 16 20:05:19.028305 2025] [security2:error] [pid 58203:tid 58203] [client 2a0b:f4c2::29:47794] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.odinathletes.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.odinathletes.com"] [uri "/thletes_2023.sql"] [unique_id "aFCxP9JWJewQZEd2vCS8tQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-14 16:14:58
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 14 12:14:53.536637 2025] [security2:error] [pid 2108008:tid 2108008] [client 2a0b:f4c2::29:35916] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||holistichealth4u2.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "holistichealth4u2.com"] [uri "/daily.sql"] [unique_id "aE2f_TzWqR0BYO5dAI_5EAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-05-30 11:15:26
(1 year ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
LRob
2025-05-30 10:45:37
(1 year ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ต๐ฑ
strefapi_com
2025-05-09 11:35:18
(1 year ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 14:25:52
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 05 10:25:46.535305 2025] [security2:error] [pid 2816076:tid 2816076] [client 2a0b:f4c2::29:16124] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jimrichardart.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jimrichardart.com"] [uri "/adminer.sql"] [unique_id "aBjKalE3pVHgefn5MayZtwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 00:53:51
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 20:53:46.086014 2025] [security2:error] [pid 1129275:tid 1129275] [client 2a0b:f4c2::29:2006] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dbfitwell.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dbfitwell.com"] [uri "/adminer.sql"] [unique_id "aBgMGj8GDt75Vcr9WmStuwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-04 11:22:16
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 07:22:11.060244 2025] [security2:error] [pid 3520870:tid 3520974] [client 2a0b:f4c2::29:17370] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dcmproductionsgroup.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dcmproductionsgroup.com"] [uri "/adminer.sql"] [unique_id "aBdN4_TYLcBjLtMXlYtNNQAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-03 22:51:14
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 03 18:51:11.165412 2025] [security2:error] [pid 3739607:tid 3739607] [client 2a0b:f4c2::29:53884] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ketsuri.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ketsuri.com"] [uri "/adminer.sql"] [unique_id "aBad35z7IGLs3EeJg327PwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-03 21:43:25
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 03 17:43:18.366478 2025] [security2:error] [pid 458196:tid 458196] [client 2a0b:f4c2::29:4382] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||campos.tv|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "campos.tv"] [uri "/bd.sql"] [unique_id "aBaN9sE_99GfdjrfdwmefwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-25 23:57:01
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::29 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 25 19:56:51.800506 2025] [security2:error] [pid 3162992:tid 3162992] [client 2a0b:f4c2::29:40414] [client 2a0b:f4c2::29] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.frenchla.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.frenchla.com"] [uri "/administrator/backups/wp-sql.sql"] [unique_id "aAwhQ3es-ryQbvelkce99gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack