πΊπΈ
TPI-Abuse
2025-10-03 01:52:17
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 21:52:08.051219 2025] [security2:error] [pid 3749765:tid 3749765] [client 2001:67c:89c:702:1ce:1ce:babe:7:65276] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||calogerolawfirm.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "calogerolawfirm.com"] [uri "/wordpress.sql"] [unique_id "aN8sSK1ienQ1XmPU_yBztgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-25 12:18:48
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 25 08:18:40.159384 2025] [security2:error] [pid 19422:tid 19422] [client 2001:67c:89c:702:1ce:1ce:babe:7:65484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||penguinexpressmag.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "penguinexpressmag.com"] [uri "/penguinexpre.sql"] [unique_id "aNUzIEzy2BY0h9XYD8hFsAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-17 21:36:24
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 17 17:36:16.734744 2025] [security2:error] [pid 1757:tid 1757] [client 2001:67c:89c:702:1ce:1ce:babe:7:65230] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||proinsaca.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "proinsaca.com"] [uri "/ca.sql"] [unique_id "aMsp0DUPooYdq9-SuUc7kQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-02 07:28:06
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 02 03:28:02.954592 2025] [security2:error] [pid 10786:tid 10786] [client 2001:67c:89c:702:1ce:1ce:babe:7:64732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "desertvacationvillas.com"] [uri "/wp-config.php.zip"] [unique_id "aLacgtUergA8VZaQOX0QKQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-27 14:03:40
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 27 10:03:31.637684 2025] [security2:error] [pid 30527:tid 30527] [client 2001:67c:89c:702:1ce:1ce:babe:7:64700] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.visionremota.info|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.visionremota.info"] [uri "/nremota.sql"] [unique_id "aK8QM3IKzCkrU1fJLSqlegAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xmission.com
2025-08-23 04:32:06
(10 months ago)
Blocked by UFW (TCP on 8333)
Source port: 64426
Packet length: 80
This report (for 2001:067c:089c:0 ...
show more
Blocked by UFW (TCP on 8333)
Source port: 64426
Packet length: 80
This report (for 2001:067c:089c:0702:01ce:01ce:babe:0007) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
π§πͺ
cmbplf
2025-08-22 11:40:39
(10 months ago)
566 limiting connections by zone (11m59sfromnow)
DDoS Attack
πΊπΈ
TPI-Abuse
2025-07-29 11:20:41
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 29 07:20:34.995008 2025] [security2:error] [pid 9818:tid 9818] [client 2001:67c:89c:702:1ce:1ce:babe:7:65006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starvationacres.us"] [uri "/wp-config.php~"] [unique_id "aIiugiFYCXyEPsnVVVGNmAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-20 03:29:43
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 19 23:29:33.554767 2025] [security2:error] [pid 20841:tid 20841] [client 2001:67c:89c:702:1ce:1ce:babe:7:64484] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tireking.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tireking.com"] [uri "/schema.sql"] [unique_id "aHxinfmcCykHMS3_9ZYjpgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-10 04:15:43
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 10 00:15:33.932725 2025] [security2:error] [pid 8411:tid 8411] [client 2001:67c:89c:702:1ce:1ce:babe:7:64268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/ns-2022.sql"] [unique_id "aG8-ZRkTwELCS8eP-RdkWwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
on-com
2025-05-28 05:23:24
(1 year ago)
URL scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-16 21:24:37
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 16 17:24:28.559237 2025] [security2:error] [pid 1357964:tid 1357964] [client 2001:67c:89c:702:1ce:1ce:babe:7:64702] [client 2001:67c:89c:702:1ce:1ce:babe:7] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||sandiegoautostarsmog.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sandiegoautostarsmog.com"] [uri "/adminer.sql"] [unique_id "aCetDH02YHbt-6sL0gw60gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-09 00:55:41
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 20:55:34.769321 2025] [security2:error] [pid 2476331:tid 2476331] [client 2001:67c:89c:702:1ce:1ce:babe:7:64028] [client 2001:67c:89c:702:1ce:1ce:babe:7] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||simplehandymanllc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "simplehandymanllc.com"] [uri "/administrator/backups/database-sql.sql"] [unique_id "aB1Shp7z6B1XWJdc1nxf5AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-07 07:19:27
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 03:19:20.561676 2025] [security2:error] [pid 3231129:tid 3231129] [client 2001:67c:89c:702:1ce:1ce:babe:7:64664] [client 2001:67c:89c:702:1ce:1ce:babe:7] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thewhispertwins.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thewhispertwins.com"] [uri "/adminer.sql"] [unique_id "aBsJeIEVZq4RuMrMKRbn5gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-04-29 16:58:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-ex ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:89c:702:1ce:1ce:babe:7 (tor-project-exit7.dotsrc.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 29 12:58:24.988292 2025] [security2:error] [pid 2893:tid 2893] [client 2001:67c:89c:702:1ce:1ce:babe:7:65504] [client 2001:67c:89c:702:1ce:1ce:babe:7] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dougrhodes.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dougrhodes.com"] [uri "/administrator/backups/database-sql.sql"] [unique_id "aBEFMID8MbrkrHLXc_2K3wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack