๐บ๐ธ
TPI-Abuse
2026-01-14 12:41:32
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 07:41:26.075241 2026] [security2:error] [pid 29785:tid 29785] [client 2001:67c:e28:1::2:38496] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kildarafarms.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kildarafarms.com"] [uri "/ms.sql"] [unique_id "aWeO9hXsu237FdWdvit-OwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-01-05 07:45:55
(7 months ago)
Blocked by UFW (TCP on 1)
Source port: 35690
Packet length: 80
This report (for 2001:067c:0e28:0001 ...
show more
Blocked by UFW (TCP on 1)
Source port: 35690
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0002) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-31 17:06:17
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 12:06:12.468474 2025] [security2:error] [pid 28754:tid 28754] [client 2001:67c:e28:1::2:49062] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chicmeow.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chicmeow.com"] [uri "/backup_wp.sql"] [unique_id "aVVYBLm1h4oeXSBfSMlw4wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 00:17:51
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 30 19:17:45.736757 2025] [security2:error] [pid 28516:tid 28516] [client 2001:67c:e28:1::2:53718] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hiddenmoosecorners.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hiddenmoosecorners.com"] [uri "/hiddenmoose.sql"] [unique_id "aVRrqaUIfbVtuKATVGFTqwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-26 15:58:04
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 26 10:57:55.899143 2025] [security2:error] [pid 14979:tid 14979] [client 2001:67c:e28:1::2:49944] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nolaanime.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nolaanime.com"] [uri "/weekly.sql"] [unique_id "aU6wg1957MO4A1MzMrEBrQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-12-23 16:25:20
(8 months ago)
Blocked by UFW (TCP on 16322)
Source port: 35244
Packet length: 80
This report (for 2001:067c:0e28: ...
show more
Blocked by UFW (TCP on 16322)
Source port: 35244
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0002) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-20 21:59:49
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 20 16:59:41.043802 2025] [security2:error] [pid 15797:tid 15797] [client 2001:67c:e28:1::2:45224] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||johncyphers.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "johncyphers.com"] [uri "/j.sql"] [unique_id "aUccTdWYYSSzgRKeW9IG_QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-12-20 08:34:06
(8 months ago)
Blocked by UFW (TCP on 42823)
Source port: 52690
Packet length: 80
This report (for 2001:067c:0e28: ...
show more
Blocked by UFW (TCP on 42823)
Source port: 52690
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0002) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-14 18:40:14
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 14 13:40:07.639547 2025] [security2:error] [pid 31096:tid 31176] [client 2001:67c:e28:1::2:39026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paylessformedicine.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paylessformedicine.com"] [uri "/paylessf.sql"] [unique_id "aT8Eh2kCKhqoadgYVqHi7gAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-12 19:21:56
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 12 14:21:52.710646 2025] [security2:error] [pid 25018:tid 25018] [client 2001:67c:e28:1::2:37752] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||speedgo.mx|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "speedgo.mx"] [uri "/backup.sql"] [unique_id "aTxrUC-zZbLLUqnk0XTLoQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-12-11 17:27:38
(8 months ago)
Blocked by UFW (TCP on 25329)
Source port: 35118
Packet length: 80
This report (for 2001:067c:0e28: ...
show more
Blocked by UFW (TCP on 25329)
Source port: 35118
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0002) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-10 19:23:20
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 14:23:16.063675 2025] [security2:error] [pid 31918:tid 31918] [client 2001:67c:e28:1::2:36212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mayiasteadman.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mayiasteadman.com"] [uri "/may.sql"] [unique_id "aTnIpKlSePchXIHNTxKkDwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-12-10 16:54:25
(8 months ago)
Blocked by UFW (TCP on 51472)
Source port: 57594
Packet length: 80
This report (for 2001:067c:0e28: ...
show more
Blocked by UFW (TCP on 51472)
Source port: 57594
Packet length: 80
This report (for 2001:067c:0e28:0001:0000:0000:0000:0002) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2025-12-09 10:40:16
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 05:40:12.780152 2025] [security2:error] [pid 18331:tid 18331] [client 2001:67c:e28:1::2:35172] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arthouse-creative.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arthouse-creative.com"] [uri "/.sql"] [unique_id "aTf8jNhoufenND581GTBZQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 01:23:52
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:67c:e28:1::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 08 20:23:46.096564 2025] [security2:error] [pid 32496:tid 32496] [client 2001:67c:e28:1::2:56776] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bonnesfrequences.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bonnesfrequences.com"] [uri "/ces_com.sql"] [unique_id "aTd6IoF9b3SH6ziaixXBJQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack