๐บ๐ธ
TPI-Abuse
2025-11-28 00:38:09
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 27 19:38:01.824155 2025] [security2:error] [pid 25694:tid 25743] [client 2a0b:f4c2::7:46002] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||orthopedica.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "orthopedica.org"] [uri "/orth.sql"] [unique_id "aSju6ZfXD7sZGRc9q_NiQQAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2025-11-24 05:55:00
(7 months ago)
IPBlock protected site ID [4055-d][s=03].
Rogue crawler, does not respect robots.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-19 05:09:39
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 00:09:31.330725 2025] [security2:error] [pid 18452:tid 18454] [client 2a0b:f4c2::7:59100] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.reghay.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.reghay.com"] [uri "/.sql"] [unique_id "aR1RC-bvml9oRO9eq1C5KAAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 17:56:18
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 12:56:11.410035 2025] [security2:error] [pid 9051:tid 9051] [client 2a0b:f4c2::7:51846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||indiahouseportland.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "indiahouseportland.com"] [uri "/backup.sql"] [unique_id "aRoQOzrTb9RbpckC09LufwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2025-11-12 22:58:30
(8 months ago)
(mod_security) mod_security (id:949110) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:949110) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 05:38:54
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 00:38:46.677269 2025] [security2:error] [pid 20977:tid 20977] [client 2a0b:f4c2::7:2376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clayrivers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clayrivers.com"] [uri "/backup_wp.sql"] [unique_id "aRLL5hqyLLL76QqGbVAufwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-11 01:12:11
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 20:12:03.754540 2025] [security2:error] [pid 3002:tid 3019] [client 2a0b:f4c2::7:61646] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||conservativedemocrat.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "conservativedemocrat.com"] [uri "/conservativ.sql"] [unique_id "aRKNY5GABC26qji-xQmKUwAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-10 20:09:14
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 15:09:08.662939 2025] [security2:error] [pid 27833:tid 27833] [client 2a0b:f4c2::7:50566] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mhsalumnifoundation.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mhsalumnifoundation.org"] [uri "/.sql"] [unique_id "aRJGZBLTpv_lMBam5fLHbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 13:08:34
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 08:08:27.050306 2025] [security2:error] [pid 7899:tid 7899] [client 2a0b:f4c2::7:22546] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kvaziri.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kvaziri.com"] [uri "/ziri.sql"] [unique_id "aQ9Ayz-JOJgIPVCOfBhsGwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 18:14:08
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 13:14:00.782670 2025] [security2:error] [pid 19652:tid 19652] [client 2a0b:f4c2::7:35264] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ultratecnologia.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ultratecnologia.com"] [uri "/ia.sql"] [unique_id "aQzlaNsWJL7_ozOmCtiztAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-06 07:01:31
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 06 02:01:27.594392 2025] [security2:error] [pid 8461:tid 8461] [client 2a0b:f4c2::7:20020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||serranoscoffee.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "serranoscoffee.com"] [uri "/backups.sql"] [unique_id "aQxHx99ddr0XOaIM76MwCwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-05 07:04:50
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 02:04:46.482951 2025] [security2:error] [pid 13160:tid 13160] [client 2a0b:f4c2::7:50910] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bigislandhawaiirealestate.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bigislandhawaiirealestate.com"] [uri "/bigislan.sql"] [unique_id "aQr3DhMlnHXyrrRDriEFwAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-05 05:46:07
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 05 00:46:03.535597 2025] [security2:error] [pid 14239:tid 14239] [client 2a0b:f4c2::7:61962] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fundingworkingcapital.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fundingworkingcapital.com"] [uri "/workingcapital.sql"] [unique_id "aQrkmxMuGnjbch3BTNWYVwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
ketovoila.pl
2025-11-03 10:47:39
(8 months ago)
ketovoila.pl HONEYPOT traffic: count=17, paths=17; sample_path=ketovoila.pl/psychopetla.php; UA=Mozi ...
show more
ketovoila.pl HONEYPOT traffic: count=17, paths=17; sample_path=ketovoila.pl/psychopetla.php; UA=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36; window=2025-11-03T10:14:30Z..2025-11-03T10:14:25Z
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-30 05:56:38
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 30 01:56:32.301486 2025] [security2:error] [pid 4147:tid 4147] [client 2a0b:f4c2::7:47782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johncyphers.com"] [uri "/wp-config.phpb"] [unique_id "aQL-EGPLvR2iMGLBiFGNswAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack