๐บ๐ธ
TPI-Abuse
2025-10-18 00:03:25
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 17 20:03:19.534883 2025] [security2:error] [pid 29151:tid 29151] [client 2a0b:f4c2::7:3204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fatbastardcompetition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fatbastardcompetition.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aPLZR6WPmeif9WleQIvElAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-15 10:46:21
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 15 06:46:11.332158 2025] [security2:error] [pid 1266:tid 1266] [client 2a0b:f4c2::7:46882] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ohanameetup.party|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ohanameetup.party"] [uri "/nameetup.sql"] [unique_id "aO97c66ot_u9BkOl8xT1WwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-14 21:38:19
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 14 17:38:11.277664 2025] [security2:error] [pid 28337:tid 28337] [client 2a0b:f4c2::7:12842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||puckerbikini.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puckerbikini.com"] [uri "/kini.sql"] [unique_id "aO7Cw7N_MiHN1udrSU0S3wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-13 15:50:15
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 13 11:50:07.146160 2025] [security2:error] [pid 15170:tid 15170] [client 2a0b:f4c2::7:36248] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||grandpont-house.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grandpont-house.org"] [uri "/pont-house.sql"] [unique_id "aO0fr-0CjPler0fLLTB1swAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-13 12:49:45
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 13 08:49:38.824921 2025] [security2:error] [pid 24102:tid 24102] [client 2a0b:f4c2::7:47608] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jacquelineperriam.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jacquelineperriam.com"] [uri "/elineperriam.sql"] [unique_id "aOz1YvbIXXN8Xut2a30XsQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-10-12 06:19:05
(9 months ago)
Blocked by UFW (TCP on 8333)
Source port: 21112
Packet length: 80
This report (for 2a0b:f4c2:0000:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 21112
Packet length: 80
This report (for 2a0b:f4c2:0000:0000:0000:0000:0000:0007) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-10-08 06:51:07
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 08 02:51:04.128158 2025] [security2:error] [pid 11394:tid 11394] [client 2a0b:f4c2::7:54946] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||circleinthesquare.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "circleinthesquare.org"] [uri "/quare.sql"] [unique_id "aOYJ2MKBJzOzjLkw2uzyDgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-08 03:42:34
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 07 23:42:30.061807 2025] [security2:error] [pid 11822:tid 11822] [client 2a0b:f4c2::7:34644] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.williamcline.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.williamcline.com"] [uri "/liamcline.sql"] [unique_id "aOXdphLyNC_v09yuiV5P1gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-07 19:56:34
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 07 15:52:03.410824 2025] [security2:error] [pid 17116:tid 17174] [client 2a0b:f4c2::7:58950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockabyecotons.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockabyecotons.com"] [uri "/rock.sql"] [unique_id "aOVvYzYuAJyN141J-2PIbAAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
weblite
2025-10-06 10:15:53
(9 months ago)
WP_EXPLOIT_PROBE WP_MALWARE_PROBE
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-03 19:09:57
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 15:09:50.898078 2025] [security2:error] [pid 20935:tid 20935] [client 2a0b:f4c2::7:26394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||newmooncafe.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "newmooncafe.com"] [uri "/ewmooncafe.sql"] [unique_id "aOAffugXJMu0Dmj3bmRFGwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rafled
2025-10-03 08:06:45
(9 months ago)
attempt to scan and scrape for env files and or files that expose the web app version
Bad Web Bot
๐บ๐ธ
myagent.site
2025-09-24 23:31:21
(9 months ago)
Blocking for trying to access an exploit file: /config.php~~
Hacking
๐บ๐ธ
TPI-Abuse
2025-09-24 11:57:46
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 07:57:36.429710 2025] [security2:error] [pid 1497083:tid 1497103] [client 2a0b:f4c2::7:64288] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.property-management-companies-chicago.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.property-management-companies-chicago.com"] [uri "/operty-management-companies-chicago.sql"] [unique_id "aNPcsAzoJ3jFHwIC94iQZAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-20 19:02:49
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0b:f4c2::7 (berlin01.tor-exit.artikel10.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 20 15:02:46.113004 2025] [security2:error] [pid 8274:tid 8274] [client 2a0b:f4c2::7:29756] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||majesticsolutions.co|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "majesticsolutions.co"] [uri "/csolutions.sql"] [unique_id "aM76VsfK1juSkC3LKItjigAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack