๐บ๐ธ
TPI-Abuse
2024-12-04 13:48:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 04 08:48:30.033055 2024] [security2:error] [pid 10707:tid 10707] [client 2a0b:f4c2::4:31908] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.rentaroller.com.au"] [uri "/.git/config"] [unique_id "Z1Bdro2u1RpUga9j45vd2gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-20 11:02:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 20 06:02:31.175594 2024] [security2:error] [pid 12440:tid 12440] [client 2a0b:f4c2::4:45210] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.cvgandhes.investments"] [uri "/.git/config"] [unique_id "Zz3BxwZdFk_AxDbahVX2xQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-20 01:46:22
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 20:46:16.428980 2024] [security2:error] [pid 5543:tid 5543] [client 2a0b:f4c2::4:34632] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.4starpromotions.com"] [uri "/.git/config"] [unique_id "Zz0_aNxV5zumtV0CCxc6HwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-11-20 01:26:24
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 19 20:26:18.496944 2024] [security2:error] [pid 1031:tid 1031] [client 2a0b:f4c2::4:21780] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.lmga.net"] [uri "/.git/config"] [unique_id "Zz06us_0fcnG5L1ajHW8qAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2024-11-05 14:40:05
(1 year ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2024-09-13 09:04:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 13 05:04:41.499549 2024] [security2:error] [pid 23874:tid 23874] [client 2a0b:f4c2::4:23786] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unladenswallow.us|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unladenswallow.us"] [uri "/unla.sql"] [unique_id "ZuQAKQP9P1MrO2Ad-YGKYAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MacLotsen
2024-08-28 17:47:01
(1 year ago)
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3 ...
show more
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (SS; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-login.php HTTP/1.1" 200 3903 "https://ellenbakt.nl" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2.1 Safari/605.2.20"
berlin01.tor-exit.artikel10.org - - [28/Aug/2024:19:45:53 +0200] "POST /wp-log
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Admins@FBN
2024-08-20 06:05:22
(1 year ago)
FW-PortScan: Traffic Blocked srcport=32488 dstport=443
Port Scan
๐บ๐ธ
TPI-Abuse
2024-08-18 21:35:32
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 18 17:35:27.251251 2024] [security2:error] [pid 7812:tid 7919] [client 2a0b:f4c2::4:51564] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.mabinogion.info"] [uri "/.git/config"] [unique_id "ZsJpH_0N7jPohhwRPpMDmQAAAgE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-17 23:15:26
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 17 19:15:18.042338 2024] [security2:error] [pid 11340:tid 11351] [client 2a0b:f4c2::4:20140] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.bullfrogspond.com"] [uri "/.git/config"] [unique_id "ZsEvBvADsXquj6g4otD05QAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-15 16:56:11
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 15 12:56:05.729346 2024] [security2:error] [pid 19779:tid 19779] [client 2a0b:f4c2::4:9782] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||naominixon.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "naominixon.com"] [uri "/backup.sql"] [unique_id "Zr4zJd3IkYkIOF_G1HywFwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-07 11:50:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 07 07:50:13.064989 2024] [security2:error] [pid 11114:tid 11114] [client 2a0b:f4c2::4:60798] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||havenlaneministries.com|F|2"] [data ".cfg"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "havenlaneministries.com"] [uri "/wp-config.cfg"] [unique_id "ZrNfdQQsg4XijbVbPY1CawAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-06 05:28:23
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 06 01:28:18.784425 2024] [security2:error] [pid 29619:tid 29619] [client 2a0b:f4c2::4:33284] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.systemcapacityoptimization.com"] [uri "/.git/config"] [unique_id "ZrG0cmo8GAUYLcKe8PRZbAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-06 03:18:18
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 23:18:13.635475 2024] [security2:error] [pid 9673:tid 9673] [client 2a0b:f4c2::4:3018] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.garrelsms.com"] [uri "/.git/config"] [unique_id "ZrGV9fVovQpbT-n87tJ5zAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-06 02:06:47
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::4 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 22:06:42.243719 2024] [security2:error] [pid 11936:tid 11936] [client 2a0b:f4c2::4:37426] [client 2a0b:f4c2::4] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.hypinc.net"] [uri "/.git/config"] [unique_id "ZrGFMltAZKzE0lGR6kgJ8wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack