๐บ๐ธ
TPI-Abuse
2025-11-09 05:07:01
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 09 00:06:56.908195 2025] [security2:error] [pid 11436:tid 11436] [client 2a0b:f4c2::3:48790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teleplussolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teleplussolutions.com"] [uri "/wp.sql"] [unique_id "aRAhcJflVNYTBc0tulhtDQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 18:16:29
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 13:16:25.344128 2025] [security2:error] [pid 19645:tid 19645] [client 2a0b:f4c2::3:3602] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ultratecnologia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ultratecnologia.com"] [uri "/cnologia.sql"] [unique_id "aQzl-VrH3hePGAZsK1GQZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-04 09:01:38
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 04:01:34.678354 2025] [security2:error] [pid 4016:tid 4016] [client 2a0b:f4c2::3:42760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bigislandhawaiirealestate.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bigislandhawaiirealestate.com"] [uri "/waiirealestate.sql"] [unique_id "aQnA7h4iJvSJifYJ94FvCQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-01 11:52:58
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 01 07:52:52.324424 2025] [security2:error] [pid 3643:tid 3671] [client 2a0b:f4c2::3:53644] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||managementlaw.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "managementlaw.com"] [uri "/manageme.sql"] [unique_id "aQX0lP6VUVOJF02AERiKCgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2025-10-28 11:51:10
(11 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ณ๐ฑ
Mangelot Hosting
2025-10-26 04:09:04
(11 months ago)
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::3 (Unknown): 1 in the last 3600 secs; Ports: *; Dire ...
show more
(db_admin_scan) srv102 DB admin scan 2a0b:f4c2::3 (Unknown): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-21 01:06:22
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 20 21:06:17.056313 2025] [security2:error] [pid 29578:tid 29578] [client 2a0b:f4c2::3:36760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lahamradio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lahamradio.com"] [uri "/lahamrad.sql"] [unique_id "aPbciQ1Mu3y8O2EzJND12wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-20 23:55:58
(11 months ago)
(modsecurity) srv102 ModSecurity 2a0b:f4c2::3 (Unknown): 5 in the last 3600 secs; Ports: *; Directio ...
show more
(modsecurity) srv102 ModSecurity 2a0b:f4c2::3 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฉ๐ช
on-com
2025-10-18 05:16:59
(11 months ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-17 13:59:25
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 09:59:20.865025 2025] [security2:error] [pid 16831:tid 16831] [client 2a0b:f4c2::3:61864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.grandriverhomes.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.grandriverhomes.com"] [uri "/grandriverhom.sql"] [unique_id "aPJLuNbEU9CEnRl8nAU4hgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-10-17 11:54:36
(11 months ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-16 18:21:57
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 16 14:21:53.744501 2025] [security2:error] [pid 3813:tid 3813] [client 2a0b:f4c2::3:52116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serranoscoffee.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serranoscoffee.com"] [uri "/serranosc.sql"] [unique_id "aPE3wfUnxVWpj5QswpsBggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-12 10:31:03
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 12 06:30:56.580507 2025] [security2:error] [pid 9441:tid 9441] [client 2a0b:f4c2::3:18204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||circleinthesquare.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circleinthesquare.org"] [uri "/circleinthesquare.sql"] [unique_id "aOuDYPzOvqDQvr0OVfVchgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-10-12 07:28:39
(11 months ago)
(modsecurity) srv102 ModSecurity 2a0b:f4c2::3 (Unknown): 5 in the last 3600 secs; Ports: *; Directio ...
show more
(modsecurity) srv102 ModSecurity 2a0b:f4c2::3 (Unknown): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-11 13:22:42
(11 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::3 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 11 09:22:37.200584 2025] [security2:error] [pid 4477:tid 4477] [client 2a0b:f4c2::3:3212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tgdingenieria.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tgdingenieria.com"] [uri "/eria.sql"] [unique_id "aOpaHao_DiLJYIWba3r5pAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack